Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8vw-8vgh-22r9

Опубликовано: 18 июл. 2025
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

XXL-JOB is vulnerable to SSRF attacks

A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Пакеты

Наименование

com.xuxueli:xxl-job-core

maven
Затронутые версииВерсия исправления

<= 3.1.1

Отсутствует

EPSS

Процентиль: 12%
0.00043
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 месяцев назад

A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 12%
0.00043
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-918