Description
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.
Remediation
References
https://github.com/xuxueli/xxl-conf/issues/61
Related Vulnerabilities
CVE-2020-36182 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-31093 Vulnerability in npm package next-auth
CVE-2023-49293 Vulnerability in npm package vite
CVE-2018-1000006 Vulnerability in npm package electron
CVE-2023-46652 Vulnerability in maven package org.jenkins-ci.plugins:lambdatest-automation