Description
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
Remediation
References
https://www.ccsq8.com/issues.html
Related Vulnerabilities
CVE-2013-7370 Vulnerability in npm package connect
CVE-2020-2296 Vulnerability in maven package org.jenkins-ci.plugins:shared-objects
CVE-2019-12086 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash
CVE-2018-16487 Vulnerability in npm package lodash.defaultsdeep