Medium severity6.1NVD Advisory· Published Dec 27, 2020· Updated Jun 17, 2026
CVE-2020-29204
CVE-2020-29204
Description
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xuxueli:xxl-job-coreMaven | < 2.3.0 | 2.3.0 |
Affected products
3- XXL-JOB/XXL-JOBdescription
Patches
Vulnerability mechanics
References
4- github.com/xuxueli/xxl-job/issues/2083nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wc73-w5r9-x9pcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-29204ghsaADVISORY
- github.com/xuxueli/xxl-job/commit/227628567354d3c156951009d683c6fec3006e0eghsaWEB
News mentions
0No linked articles in our index yet.