SCA: Xuxueli xxl-job template injection vulnerability (GHSA-2v42-xp3j-47m4)

low Tenable Self-Hosted Container Security Plugin ID 435133

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability classified as problematic was found in Xuxueli xxl-job version 2.4.0. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480. (CVE-2024-3366)

See Also

https://github.com/advisories/GHSA-2v42-xp3j-47m4

Plugin Details

Severity: Low

ID: 435133

Version: Revision 1.0

Type: Local

Family: SCA Checks

Published: 8/28/2025

Updated: 8/28/2025

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

CVSS v3

Risk Factor: Low

Base Score: 3.5

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Vulnerability Information

Vulnerability Publication Date: 4/6/2024