PT-2025-30048 · Xxl-Job · Xxl-Job

Zast.Ai

·

Publicado

2025-07-18

·

Atualizado

2025-07-18

·

CVE-2025-7789

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions xxl-job versions up to 3.1.1
Description A flaw exists within the makeToken function located in src/main/java/com/xxl/job/admin/controller/IndexController.java of the Token Generation component. This issue involves password hashing with insufficient computational effort, potentially allowing for unauthorized access. The attack can be initiated remotely, but is considered difficult to exploit. The exploit details have been publicly disclosed.
Recommendations Update to a version beyond 3.1.1.

Exploit

Correção

Inadequate Encryption Strength

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-7789
GHSA-565H-44M8-4C2V

Produtos afetados

Xxl-Job