XXL-JOB是许雪里(xuxueli)个人开发者的一个分布式任务调度平台。 XXL-JOB 3.3.2及之前版本存在加密问题漏洞,该漏洞源于组件OpenAPI Endpoint中文件xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java的未知函数参数default_token操作导致使用硬编码加密密钥,可能允许远程攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7305 | 6.3 MEDIUM | Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request for |
| CVE-2026-7303 | 3.7 LOW | Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection |
No comments yet