Impact
The vulnerability is a Server‑Side Request Forgery in the xxl‑job‑admin/jobinfo/trigger component of xxl‑job 3.4.0 that permits an authenticated attacker to supply a crafted HTTP request. The flaw allows the application to issue outbound requests to arbitrary URLs, enabling the attacker to scan internal resources.
Affected Systems
The affected product is the xxl‑job administration server, version 3.4.0. No vendor product names or additional versions are listed in the report.
Risk and Exploitability
The CVSS score is 6.5, and the EPSS score is listed as less than 1 % and the vulnerability is not in the CISA KEV catalog, indicating a very low current probability of exploitation. The attack requires legitimate authentication to the application, so only users with valid credentials can exploit the SSRF. Although the immediate threat level is low, the potential for internal resource access makes the impact significant if the flaw is leveraged. Network isolation or stringent access controls are recommended to reduce risk.
OpenCVE Enrichment