PT-2026-90727 · Xuxueli · Xxl-Job
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xuxueli xxl-job versions prior to 3.4.3
Description
A code injection flaw exists that allows for remote exploitation. The issue resides in the
GroovyClassLoader.parseClass() function within the xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java file.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the
GroovyClassLoader.parseClass() function to minimize the risk of exploitation.Exploit
Code Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xxl-Job