CVE-2023-36106
Description
PowerJob 4.3.2 and earlier has an incorrect access control vulnerability in the /container/list endpoint, allowing unauthenticated disclosure of sensitive container information via the appId parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
PowerJob 4.3.2 and earlier has an incorrect access control vulnerability in the /container/list endpoint, allowing unauthenticated disclosure of sensitive container information via the appId parameter.
Vulnerability
Description
CVE-2023-36106 is an incorrect access control vulnerability in the distributed task scheduling and computing framework PowerJob, affecting versions 4.3.2 and earlier. The vulnerability exists in the /container/list endpoint, which does not properly enforce authorization checks when handling the appId parameter. As a result, an unauthenticated remote attacker can query container information without any valid credentials or session tokens.[2][3]
Exploitation
Exploitation is straightforward and requires no authentication. An attacker simply sends a crafted HTTP request to the /container/list interface, supplying a valid or enumerated appId value as a parameter. The application processes the request and returns the corresponding container details without verifying the requestor's identity or permissions. This means any remote user who can reach the vulnerable API endpoint can leverage it to extract data.[3]
Impact
The impact is the unauthenticated disclosure of sensitive information related to containers. An attacker can enumerate application IDs and retrieve metadata, configuration details, or other internal data exposed through the container list API. This information leakage could facilitate further attacks or expose business-critical configurations, undermining the security of the deployment.[2][3]
Mitigation
As of the publication date, PowerJob users should upgrade to a version newer than 4.3.2 where the access control issue is addressed. No workarounds are detailed in the available references. The project source code is hosted on Gitee and may include patches in later releases.[1][2]
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tech.powerjob:powerjobMaven | <= 4.3.2 | — |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.