Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2020-36378 Vulnerability in npm package aaptjs
CVE-2020-36144 Vulnerability in npm package redash
CVE-2016-8608 Vulnerability in maven package org.jbpm:jbpm-designer-client
CVE-2019-11002 Vulnerability in maven package org.webjars.npm:materialize-css
CVE-2023-34464 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates