CVE-2022-36157: High severity xxl-job vulnerability
Published Aug 19, 2022
·Updated
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Affected Software
2 affected componentsFixes available
maven/com.xuxueli:xxl-job<=2.3.1
2.4.0
Xuxueli xxl-job<=2.3.1
Event History
Aug 19, 2022
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
Description
Aug 20, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this XXL-JOB vulnerability?
The vulnerability ID for this XXL-JOB vulnerability is CVE-2022-36157.
2
What is the severity rating of CVE-2022-36157?
The severity rating of CVE-2022-36157 is 8.8 (high).
3
What is the affected software for CVE-2022-36157?
The affected software for CVE-2022-36157 is XXL-JOB all versions as of 11 July 2022.
4
What is the impact of CVE-2022-36157?
The impact of CVE-2022-36157 is the ability to execute admin functions with a low privilege account.
5
Is there a fix available for CVE-2022-36157?
Currently, there is no information available regarding a fix for CVE-2022-36157. It is recommended to follow the recommendations provided by the vendor or security advisories for updates.