Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2018-3714 Vulnerability in npm package node-srv
CVE-2021-23431 Vulnerability in npm package joplin
CVE-2019-5438 Vulnerability in npm package harp
CVE-2020-17510 Vulnerability in maven package org.apache.shiro:shiro-spring-boot-web-starter
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-core