PT-2026-62413 · Git+1 · Xxl-Job
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
XXL-Job version 2.4.2
Description
An insecure direct object reference allows authenticated users to read execution log content from job groups they are not authorized to access. By supplying arbitrary sequential values to the
logId parameter at the '/logDetailCat' endpoint, attackers can enumerate log records across all job groups. This process bypasses the permission checks implemented in the '/logDetailPage' endpoint, enabling the retrieval of sensitive log content from restricted groups.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
logId parameter in the '/logDetailCat' endpoint until the issue is resolved.Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xxl-Job