PT-2024-20277 · Xxl-Job · Xxl-Job

John-Frodo

·

Published

2024-02-08

·

Updated

2024-02-15

·

CVE-2024-24113

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xxl-job versions prior to 2.4.1
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability. This vulnerability allows low-privileged users to control the executor, potentially leading to Remote Code Execution (RCE).
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the executor to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-24113
GHSA-C352-X843-GGPQ

Affected Products

Xxl-Job