Description
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2979
Related Vulnerabilities
CVE-2016-4055 Vulnerability in npm package moment
CVE-2021-23344 Vulnerability in npm package total.js
CVE-2021-23597 Vulnerability in npm package fastify-multipart
CVE-2022-25872 Vulnerability in npm package fast-string-search
CVE-2021-21619 Vulnerability in maven package org.jenkins-ci.plugins:claim