MEDIUM
Xuxueli xxl-job SampleXxlJob.java httpJobHandler server-side request forgery
Published Jul 18, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.44%
Description
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 3.1.0StatusaffectedConstraints-
- Version 3.1.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21877 Advisory
- https://github.com/advisories/GHSA-f8vw-8vgh-22r9 Advisory
- https://github.com/xuxueli/xxl-job/issues/3749 exploitissue-trackingIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7787
- https://vuldb.com/?ctiid.316848 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.316848 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.615741 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21877 | Advisory | |
| https://github.com/advisories/GHSA-f8vw-8vgh-22r9 | Advisory | |
| https://github.com/xuxueli/xxl-job/issues/3749 | exploitissue-trackingIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-7787 | ||
| https://vuldb.com/?ctiid.316848 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.316848 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.615741 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jul 18, 2025
Updated Jul 18, 2025
Reserved Jul 18, 2025
Link CVE-2025-7787
CISA Vulnrichment
Updated Jul 18, 2025
ENISA EUVD
EUVD-2025-21877 GHSA-F8VW-8VGH-22R9 Assigner VulDB
Published Jul 18, 2025
Updated Jul 18, 2025
Exploited since n/a
Link EUVD-2025-21877