CVE-2024-3366: Xuxueli xxl-job Template JdkSerializeTool.java deserialize injection
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.
Other sources
A vulnerability classified as problematic was found in Xuxueli xxl-job version 2.4.0. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3366?
CVE-2024-3366 is classified as a problematic vulnerability.
How does CVE-2024-3366 affect Xuxueli xxl-job?
CVE-2024-3366 affects the deserialization function in the Template Handler component of Xuxueli xxl-job, allowing for potential code injection.
Which versions of the software are affected by CVE-2024-3366?
CVE-2024-3366 affects Xuxueli xxl-job versions up to 2.4.1.
How can I fix CVE-2024-3366?
To fix CVE-2024-3366, it is recommended to update Xuxueli xxl-job to a version above 2.4.1.
Is there an exploit available for CVE-2024-3366?
Yes, CVE-2024-3366 can be exploited due to the injection vulnerabilities present in the affected versions.