First published: Mon May 23 2022(Updated: )
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xuxueli xxl-job | =2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29002 is a Cross-Site Request Forgery (CSRF) vulnerability in XXL-Job v2.3.0 that allows attackers to create administrator accounts.
The CSRF vulnerability in XXL-Job v2.3.0 allows attackers to perform unauthorized actions on behalf of authenticated users by tricking them into clicking on a maliciously crafted link or visiting a malicious website.
CVE-2022-29002 has a severity rating of 8.8 (high).
To fix the CSRF vulnerability in XXL-Job v2.3.0, it is recommended to upgrade to a patched version that addresses the issue.
You can find more information about CVE-2022-29002 on the official XXL-Job GitHub page: https://github.com/xuxueli/xxl-job/issues/2821