CVE-2024-3366 is a critical injection vulnerability (CWE-502, CWE-74) found in Xuxueli xxl-job versions up to 2.4.1. Specifically, it affects the deserialize function within the JdkSerializeTool.java file of the Template Handler component. This vulnerability has a CVSS score of 9.8 (Critical), indicating it can be exploited remotely with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While public exploit code exists and there's significant community discussion, it is not currently listed in CISA's KEV catalog or actively exploited according to available intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.1CPE matchmatch criteria | cpe:2.3:a:xuxueli:xxl-job:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.