GHSA-4m5h-5v4q-4xgq

Suggest an improvement
Source
https://github.com/advisories/GHSA-4m5h-5v4q-4xgq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-4m5h-5v4q-4xgq/GHSA-4m5h-5v4q-4xgq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4m5h-5v4q-4xgq
Aliases
  • CVE-2025-2622
Published
2025-03-22T18:30:25Z
Modified
2025-03-24T20:34:26.086520Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Details

A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipulation of the argument nodeExpression leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Database specific
{
    "nvd_published_at": "2025-03-22T17:15:35Z",
    "severity": "MODERATE",
    "github_reviewed_at": "2025-03-24T19:57:55Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20",
        "CWE-502"
    ]
}
References

Affected packages

Maven / com.aizuda:snail-job

Package

Name
com.aizuda:snail-job
View open source insights on deps.dev
Purl
pkg:maven/com.aizuda/snail-job

Affected ranges

Affected versions

1.*
1.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-4m5h-5v4q-4xgq/GHSA-4m5h-5v4q-4xgq.json"