Description
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3333
Related Vulnerabilities
CVE-2021-23374 Vulnerability in npm package ps-visitor
CVE-2011-1772 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2017-1000190 Vulnerability in maven package org.simpleframework:simple-xml
CVE-2015-0250 Vulnerability in maven package batik:batik-transcoder
CVE-2022-41404 Vulnerability in maven package org.ini4j:ini4j