Description
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3333
Related Vulnerabilities
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.13
CVE-2020-7702 Vulnerability in npm package templ8
CVE-2023-26120 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2022-25855 Vulnerability in npm package create-choo-app3
CVE-2020-15999 Vulnerability in maven package org.webjars.npm:electron