'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-28 | |
| Rule Name: | PowerJob 4.3.2 List Method Unauthorized Access Vulnerability (CVE-2023-29923) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | PowerJob is an open source distributed task scheduling framework. PowerJob V4.3.1 version contains a security vulnerability due to the JobController # listJobs method not verifying user identity. Attackers can send a POST request to the/job/list interface, specifying the appId parameter to list the corresponding running task list and their status information. | |
| Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://github.com/PowerJob/PowerJob/issues/587 https://cxsecurity.com/cveshow/CVE-2023-29923/ |
|
| Solutions |
|---|
| Refer to the announcement or patch by the vendor: https://github.com/PowerJob/PowerJob/releases/tag/v4.3.2 |