MEDIUM
Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash
Published Jul 18, 2025
6.3
MEDIUMCVSS 4.0
EPSS 0.29%
Description
A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational effort. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 3.1.0StatusaffectedConstraints-
- Version 3.1.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21882 Advisory
- https://github.com/advisories/GHSA-565h-44m8-4c2v Advisory
- https://github.com/xuxueli/xxl-job/commit/cb1bd548a6d9512aab6f1ba9c5686de62f863fcd
- https://github.com/xuxueli/xxl-job/issues/3751 exploitissue-trackingIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7789
- https://vuldb.com/?ctiid.316850 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.316850 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.615760 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21882 | Advisory | |
| https://github.com/advisories/GHSA-565h-44m8-4c2v | Advisory | |
| https://github.com/xuxueli/xxl-job/commit/cb1bd548a6d9512aab6f1ba9c5686de62f863fcd | ||
| https://github.com/xuxueli/xxl-job/issues/3751 | exploitissue-trackingIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-7789 | ||
| https://vuldb.com/?ctiid.316850 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.316850 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.615760 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jul 18, 2025
Updated Jul 18, 2025
Reserved Jul 18, 2025
Link CVE-2025-7789
CISA Vulnrichment
Updated Jul 18, 2025
ENISA EUVD
EUVD-2025-21882 GHSA-565H-44M8-4C2V Assigner VulDB
Published Jul 18, 2025
Updated Jul 18, 2025
Exploited since n/a
Link EUVD-2025-21882