XXL-JOB contains a Command execution vulnerability in background tasks
Critical severity
GitHub Reviewed
Published
Sep 29, 2022
to the GitHub Advisory Database
•
Updated May 13, 2024
Description
Published by the National Vulnerability Database
Sep 28, 2022
Published to the GitHub Advisory Database
Sep 29, 2022
Reviewed
Sep 30, 2022
Last updated
May 13, 2024
XXL-JOB versions 2.2.0 and prior contain a Command execution vulnerability in background tasks.
NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
References