com.xuxueli:xxl-job-core@1.7.1 vulnerabilities
-
latest version
2.4.1
-
first published
8 years ago
-
latest version published
7 months ago
-
licenses detected
- [1.4.1,1.8.0)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the com.xuxueli:xxl-job-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
com.xuxueli:xxl-job-core is a distributed task scheduling framework. Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine via the How to fix Improper Neutralization of Special Elements Used in a Template Engine? Upgrade |
[0,2.4.1)
|
com.xuxueli:xxl-job-core is a distributed task scheduling framework. Affected versions of this package are vulnerable to Command Injection via the background tasks due to improper input validation. Note: This vulnerability doesn't have enough evidence for its exploitability. How to fix Command Injection? There is no fixed version for |
[0,)
|
com.xuxueli:xxl-job-core is a distributed task scheduling framework. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) which may allow modifying a user's password. How to fix Cross-site Request Forgery (CSRF)? There is no fixed version for |
[0,)
|