Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

阿里云扫描spring框架漏洞 #3598

Open
cnn007 opened this issue Dec 24, 2024 · 3 comments
Open

阿里云扫描spring框架漏洞 #3598

cnn007 opened this issue Dec 24, 2024 · 3 comments

Comments

@cnn007
Copy link

cnn007 commented Dec 24, 2024

Please answer some questions before submitting your issue. Thanks!

Which version of XXL-JOB do you using?

v2.4.2

Expected behavior

Actual behavior

Steps to reproduce the behavior

Other information

image

@cnn007
Copy link
Author

cnn007 commented Dec 24, 2024

image
这3个修复了,阿里有缓存。

@lialzm
Copy link

lialzm commented Dec 25, 2024

我这边扫出来也是有

CVE-2024-38819

软件:xxl-job 2.4.2
命中:["xxl-job extendField.access_token_configed equals false"]
路径:/app.jar(BOOT-INF/lib/xxl-job-core-2.4.2.jar)
进程ID:102583

AVD-2023-1678172

命中:["xxl-job extendField.access_token_configed equals false"]
路径:/app.jar(BOOT-INF/lib/xxl-job-core-2.4.2.jar)
进程ID:102583

CVE-2024-38816

软件:spring 5.3.31
命中:["spring version less than equals 5.3.39"]
路径:/app.jar(BOOT-INF/lib/spring-core-5.3.31.jar)
进程ID:102583

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants