Impact
A vulnerability in Xuxueli xxl-job enables arbitrary code execution through the GroovyClassLoader.parseClass method within GlueFactory.java. The flaw allows an attacker to inject Groovy code that is subsequently executed by the job scheduler, leading to complete compromise of the host system. The weakness aligns with code injection and code execution controls, as identified by CWE-74 and CWE-94.
Affected Systems
Versions of Xuxueli xxl-job up to and including 3.4.2 are affected-job core that exposes the GlueFactory functionality, such as the default web interface or API used for job configuration.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, but the vulnerability is remotely exploitable and has publicly available proof‑of‑concepts. EPSS score of 0.00228 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker that can reach the job configuration endpoint can provide malicious compile and run without additional input validation, resulting in full remote code execution.
OpenCVE Enrichment