Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2023-46654 Vulnerability in maven package org.jenkins-ci.plugins:electricflow
CVE-2022-24847 Vulnerability in maven package org.geoserver.web:gs-web-sec-jdbc
CVE-2021-21316 Vulnerability in npm package less-openui5
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-management
CVE-2023-29205 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-xwiki