CVE-2025-7789 MEDIUM

CVE-2025-7789: Xuxueli xxl-job Token Generation IndexController.java makeToken weak password hash

Vendor Xuxueli
Product xxl-job
Weakness CWE-916
Published July 18, 2025
Last update July 18, 2025

CVSS base score

6.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

Description

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational effort. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Key dates

Disclosure timeline

July 18, 2025 CVE published
July 18, 2025 Record updated