CVE-2022-40929: OS Command Injection
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks.
Other sources
XXL-JOB versions 2.2.0 and prior contain a Command execution vulnerability in background tasks.
NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40929?
CVE-2022-40929 is a Command execution vulnerability in background tasks in XXL-JOB versions 2.2.0 and prior.
What is the severity of CVE-2022-40929?
The severity of CVE-2022-40929 is critical with a CVSS score of 9.8.
How does CVE-2022-40929 impact my system?
CVE-2022-40929 allows remote attackers to execute arbitrary commands on the affected system.
How can I fix CVE-2022-40929?
To fix CVE-2022-40929, it is recommended to update XXL-JOB to a version higher than 2.2.0.
Where can I find more information about CVE-2022-40929?
You can find more information about CVE-2022-40929 on the NIST National Vulnerability Database (NVD) at https://nvd.nist.gov/vuln/detail/CVE-2022-40929.