XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.xuxueli:xxl-job-core(Maven) | 0 | N/A | N/A |
CVSS Metrics