Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.12
CVE-2022-22885 Vulnerability in maven package cn.hutool:hutool-http
CVE-2022-23712 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-43441 Vulnerability in npm package sqlite3
CVE-2023-47322 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web