CVE-2025-14674
6.3
CVSS Score
Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Link copied!
Description
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java. The manipulation results in injection. The attack can be launched remotely. Upgrading to version 1.7.0-beta1 addresses this issue. The patch is identified as 978f316c38b3d68bb74d2489b5e5f721f6675e86. The affected component should be upgraded.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Weaknesses (CWE)
- CWE-74
References & External Links
- https://gitee.com/aizuda/snail-job/commit/978f316c38b3d68bb74d2489b5e5f721f6675e86
- https://gitee.com/aizuda/snail-job/issues/ICNUG0
- https://gitee.com/aizuda/snail-job/issues/ICNUG0#note_44321424_link
- https://gitee.com/aizuda/snail-job/releases/tag/vsj1.7.0-beta1
- https://vuldb.com/?ctiid.336403
- https://vuldb.com/?id.336403