com.xuxueli:xxl-job-core@2.4.1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the com.xuxueli:xxl-job-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Command Injection

com.xuxueli:xxl-job-core is a distributed task scheduling framework.

Affected versions of this package are vulnerable to Command Injection via the background tasks due to improper input validation.

Note: This vulnerability doesn't have enough evidence for its exploitability.

How to fix Command Injection?

There is no fixed version for com.xuxueli:xxl-job-core.

[0,)
  • M
Cross-site Request Forgery (CSRF)

com.xuxueli:xxl-job-core is a distributed task scheduling framework.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) which may allow modifying a user's password.

How to fix Cross-site Request Forgery (CSRF)?

There is no fixed version for com.xuxueli:xxl-job-core.

[0,)