Description
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2979
Related Vulnerabilities
CVE-2020-28451 Vulnerability in npm package image-tiler
CVE-2023-37903 Vulnerability in npm package vm2
CVE-2022-39249 Vulnerability in npm package matrix-js-sdk
CVE-2021-33561 Vulnerability in maven package com.shopizer:shopizer
CVE-2023-3414 Vulnerability in maven package io.jenkins.plugins:servicenow-devops