Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash

CVE Details

Basic Information

Title Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash
Type cve
Published 2025-07-18T15:14:05.920Z
Modified 2025-07-18T15:28:47.143Z

Product Information

Vendor Xuxueli
Product xxl-job
Version 3.1.0

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A vulnerability in Xuxueli xxl-job’s token generation function leads to weak password hashes, making it easier for attackers to brute-force passwords. This issue affects versions up to 3.1.1 and could allow remote attacks, though exploitation is considered difficult.
AI Severity High
AI Vendor Xuxueli
AI Product xxl-job
AI Version 3.1.0, 3.1.1

Affected Products

  • Xuxueli xxl-job 3.1.0
  • Xuxueli xxl-job 3.1.1

Additional Information

CWE List CWE-916, CWE-326
Source VulDB

Description

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational effort. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.