CVE-2023-27087: High severity xxl-job vulnerability
Published Mar 21, 2023
·Updated
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.
Affected Software
4 affected components
Xuxueli xxl-job=2.2.0
Xuxueli xxl-job=2.3.0
Xuxueli xxl-job=2.3.1
maven/com.xuxueli:xxl-job>=2.2.0<=2.3.1
Event History
Mar 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this permissions vulnerability?
The vulnerability ID for this permissions vulnerability is CVE-2023-27087.
2
What is the severity level of CVE-2023-27087?
The severity level of CVE-2023-27087 is high, with a severity value of 7.5.
3
How does the permissions vulnerability in Xuxueli xxl-job v2.2.0, v 2.3.0, and v.2.3.1 allow an attacker to obtain sensitive information?
The permissions vulnerability in Xuxueli xxl-job v2.2.0, v 2.3.0, and v.2.3.1 allows an attacker to obtain sensitive information via the pageList parameter.
4
Which versions of Xuxueli xxl-job are affected by this permissions vulnerability?
This permissions vulnerability affects Xuxueli xxl-job v2.2.0, v 2.3.0, and v.2.3.1.
5
Is there any official reference or documentation about this permissions vulnerability?
Yes, you can find more information about this permissions vulnerability in the official reference at https://github.com/xuxueli/xxl-job/issues/3096.