PT-2024-30107 · Xxl-Job · Xxl-Job
Skyblue955
·
Published
2024-08-15
·
Updated
2024-08-19
·
CVE-2024-42681
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xxl-job version 2.4.1
Description
The issue allows a remote attacker to execute arbitrary code via the Sub-Task ID component due to insecure permissions.
Recommendations
For xxl-job version 2.4.1, consider disabling the Sub-Task ID component until a patch is available to prevent remote code execution.
Exploit
Fix
Improper Preservation of Permissions
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xxl-Job