Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
During installation, installed file permissions are set to allow anyone to modify those files.
A product defines a set of insecure permissions that are inherited by objects that are created by the program.
Link | Tags |
---|---|
https://github.com/xuxueli/xxl-job/issues/3516 | issue tracking exploit |