CNNVD-202512-2571 Information

CNNVD ID

CNNVD-202512-2571

CVE-2025-14674

  • CNNVD Published: 2025-12-14

Description (Chinese)

SnailJob是aizuda开源的一个灵活、可靠且高效的分布式任务重试和任务调度平台。 SnailJob 1.6.0及之前版本存在安全漏洞,该漏洞源于对文件snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java中函数QLExpressEngine.doEval的错误操作,可能导致注入攻击。

Description (English)

SnailJob is a flexible, reliable and efficient distributed mission re-testing and tasking platform for anizuda ’ s open source. There is a security loophole in SnailJob 1.6.0 and previous versions, which stems from the mishandling of document snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/strategy/QLExpressEngine.java, QLExpressEngine.doEval, which could lead to injection attacks.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

aizuda

Published

2025-12-14

Last Modified

2026-02-24

References

https://gitee.com/aizuda/snail-job/commit/978f316c38b3d68bb74d2489b5e5f721f6675e86 https://gitee.com/aizuda/snail-job/issues/ICNUG0 https://gitee.com/aizuda/snail-job/issues/ICNUG0#note_44321424_link https://gitee.com/aizuda/snail-job/releases/tag/vsj1.7.0-beta1 https://vuldb.com/?ctiid.336403 https://vuldb.com/?id.336403

Patch

https://github.com/aizuda/snail-job/tags

Share on: