Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2022-2191 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2017-16218 Vulnerability in npm package dgard8.lab6
CVE-2020-7729 Vulnerability in maven package org.webjars.npm:grunt
CVE-2018-5673 Vulnerability in maven package org.webjars.bower:dojo
CVE-2017-12629 Vulnerability in maven package org.apache.solr:solr-core