{"id":"GHSA-2v42-xp3j-47m4","summary":"Xuxueli xxl-job template injection vulnerability","details":"A vulnerability classified as problematic was found in Xuxueli xxl-job version 2.4.0. This vulnerability affects the function `deserialize` of the file `com/xxl/job/core/util/JdkSerializeTool.java` of the component `Template Handler`. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.","aliases":["CVE-2024-3366"],"modified":"2025-05-23T18:46:07.243340Z","published":"2024-04-06T12:30:56Z","database_specific":{"nvd_published_at":"2024-04-06T11:15:08Z","cwe_ids":["CWE-502","CWE-74"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-04-08T15:42:15Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3366"},{"type":"WEB","url":"https://github.com/xuxueli/xxl-job/issues/3391"},{"type":"WEB","url":"https://github.com/xuxueli/xxl-job/commit/e3b2e1234614195390f46e26c15cd4881bd4dbe3"},{"type":"PACKAGE","url":"https://github.com/xuxueli/xxl-job"},{"type":"WEB","url":"https://github.com/xuxueli/xxl-job/blob/761de38a0b2a39706e2008e7914fba13bf4ca184/xxl-job-core/src/main/java/com/xxl/job/core/util/JdkSerializeTool.java#L4"},{"type":"WEB","url":"https://vuldb.com/?ctiid.259480"},{"type":"WEB","url":"https://vuldb.com/?id.259480"},{"type":"WEB","url":"https://vuldb.com/?submit.308180"}],"affected":[{"package":{"name":"com.xuxueli:xxl-job-core","ecosystem":"Maven","purl":"pkg:maven/com.xuxueli/xxl-job-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.4.0"}]}],"versions":["1.4.1","1.4.2","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.7.0","1.7.1","1.7.2","1.8.0","1.8.1","1.8.2","1.9.0","1.9.1","1.9.2","2.0.0","2.0.1","2.0.2","2.1.0","2.1.1","2.1.2","2.2.0","2.3.0","2.3.1","2.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-2v42-xp3j-47m4/GHSA-2v42-xp3j-47m4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}