Description
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2979
Related Vulnerabilities
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system
CVE-2018-14042 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2020-28429 Vulnerability in npm package geojson2kml
CVE-2018-3755 Vulnerability in npm package sexstatic
CVE-2017-1000486 Vulnerability in maven package org.primefaces:primefaces