References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/XXL-JOB-%E9%BB%98%E8%AE%A4-accessToken-%E8%BA%AB%E4%BB%BD%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/qq_59405467/article/details/134406720 https://cloud.tencent.com/developer/article/2436352 https://github.com/xuxueli/xxl-job/issues/3783 https://x.threatbook.com/v5/article?threatInfoID=96052 https://www.cnblogs.com/chm0d/p/17805168.html https://cloud.tencent.com/developer/article/2470145 https://www.ksyun.com/cms/notice/177.html https://kdniao.csdn.net/69d8edb154b52172bc6885ef.html https://www.xuxueli.com/xxl-job/
Related VulnerabilitiesPoCCVE-2020-23814: XXL-JOB v2.2.0 — Stored Cross Site ScriptingPoCxxljob-default-login: XXL-JOB Default LoginPoCxxl-job-default-token-bypass-rce: XXL-JOB 默认 accessToken 身份绕过漏洞PoCxxljob-executor-unauth: XXL-JOB executor - Unauthorized AccessXXL-JOB Executor /run 代码执行漏洞XXL-JOB 任务调度中心 后台任意命令执行漏洞xxl-job api未授权Hessian2反序列化漏洞XXL-JOB api未授权访问漏洞分布式任务调度平台XXL-JOB远程代码执行漏洞XXL-JOB默认accessToken身份绕过RCE漏洞XXL-JOB accessToken 权限绕过漏洞