PT-2026-108202 · Unknown+1 · Xxl-Job-Admin+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dromara Skyeye versions prior to commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321
Description
A missing authentication issue exists in the bundled xxl-job-admin
JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can send requests to the /jobinfo/addAndStart endpoint by providing attacker-supplied glueSource for GLUE SHELL, GLUE PYTHON, or GLUE POWERSHELL jobs. This allows for remote code execution on the executor host, as well as the ability to stop and delete jobs.Recommendations
Update Dromara Skyeye to a version including commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321.
Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skyeye
Xxl-Job-Admin