CVE-2024-24113
Description
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
XXL-JOB <=2.4.1 has an SSRF in the /trigger endpoint allowing low-privileged users to obtain an access token and achieve RCE on executors.
XXL-JOB, a distributed task scheduling framework, contains a Server-Side Request Forgery (SSRF) vulnerability in versions 2.4.1 and earlier [1]. The flaw resides in the /trigger endpoint of JobInfoController.java, which directly sends requests to user-supplied addresses without validation [3].
A low-privileged user without executor permissions can exploit this by crafting a request to /trigger with an arbitrary addressList parameter pointing to an attacker-controlled server. The XXL-JOB admin server will then send a request containing the XXL-JOB-ACCESS-TOKEN to that server, leaking the token [3].
With the obtained token, the attacker can call any executor and submit arbitrary tasks, leading to remote code execution (RCE) on the executor machines. The attack requires knowledge of a valid job ID, which can be enumerated [3].
As of the publication date, no official patch was available. Users should upgrade to a version beyond 2.4.1 if available, or implement input validation on the addressList parameter to restrict it to known executor addresses [1][3].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.xuxueli:xxl-jobMaven | <= 2.4.2 | — |
Affected products
2- xxl-job/xxl-jobdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-c352-x843-ggpqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-24113ghsaADVISORY
- github.com/xuxueli/xxl-job/issues/3375ghsaWEB
News mentions
0No linked articles in our index yet.