Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2018-12544 Vulnerability in maven package io.vertx:vertx-web-api-contract
CVE-2020-6457 Vulnerability in npm package electron
CVE-2022-45470 Vulnerability in maven package org.apache.hama:hama-core
CVE-2020-28480 Vulnerability in maven package org.webjars.bower:jointjs
CVE-2022-36010 Vulnerability in npm package react-editable-json-tree