PT-2025-30048 · Xxl-Job · Xxl-Job

Zast.Ai

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-7789

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions xxl-job versions up to 3.1.1
Description A flaw exists within the makeToken function located in src/main/java/com/xxl/job/admin/controller/IndexController.java of the Token Generation component. This issue involves password hashing with insufficient computational effort, potentially allowing for unauthorized access. The attack can be initiated remotely, but is considered difficult to exploit. The exploit details have been publicly disclosed.
Recommendations Update to a version beyond 3.1.1.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7789
GHSA-565H-44M8-4C2V

Affected Products

Xxl-Job