CVE-2022-29002: CSRF
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29002?
CVE-2022-29002 is a Cross-Site Request Forgery (CSRF) vulnerability in XXL-Job v2.3.0 that allows attackers to create administrator accounts.
How does the CSRF vulnerability in XXL-Job v2.3.0 work?
The CSRF vulnerability in XXL-Job v2.3.0 allows attackers to perform unauthorized actions on behalf of authenticated users by tricking them into clicking on a maliciously crafted link or visiting a malicious website.
What is the severity of CVE-2022-29002?
CVE-2022-29002 has a severity rating of 8.8 (high).
How can I fix the CSRF vulnerability in XXL-Job v2.3.0?
To fix the CSRF vulnerability in XXL-Job v2.3.0, it is recommended to upgrade to a patched version that addresses the issue.
Where can I find more information about CVE-2022-29002?
You can find more information about CVE-2022-29002 on the official XXL-Job GitHub page: https://github.com/xuxueli/xxl-job/issues/2821