Description
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2979
Related Vulnerabilities
CVE-2019-10792 Vulnerability in npm package bodymen
CVE-2021-23490 Vulnerability in npm package parse-link-header
CVE-2020-7961 Vulnerability in maven package com.liferay.portal:com.liferay.portal.impl
CVE-2020-28502 Vulnerability in npm package xmlhttprequest-ssl
CVE-2022-45921 Vulnerability in maven package io.fusionauth:fusionauth-java-client