CNNVD-202512-2571 Information
CNNVD ID
CNNVD-202512-2571
Related CVE
- CNNVD Published: 2025-12-14
Description (Chinese)
SnailJob是aizuda开源的一个灵活、可靠且高效的分布式任务重试和任务调度平台。 SnailJob 1.6.0及之前版本存在安全漏洞,该漏洞源于对文件snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java中函数QLExpressEngine.doEval的错误操作,可能导致注入攻击。
Description (English)
SnailJob is a flexible, reliable and efficient distributed mission re-testing and tasking platform for anizuda ’ s open source. There is a security loophole in SnailJob 1.6.0 and previous versions, which stems from the mishandling of document snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java, QLExpressEngine.doEval, which could lead to injection attacks.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
aizuda
Published
2025-12-14
Last Modified
2026-02-24
References
https://gitee.com/aizuda/snail-job/commit/978f316c38b3d68bb74d2489b5e5f721f6675e86 https://gitee.com/aizuda/snail-job/issues/ICNUG0 https://gitee.com/aizuda/snail-job/issues/ICNUG0#note_44321424_link https://gitee.com/aizuda/snail-job/releases/tag/vsj1.7.0-beta1 https://vuldb.com/?ctiid.336403 https://vuldb.com/?id.336403
Patch
https://github.com/aizuda/snail-job/tags
Share on: