Description
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
Remediation
References
https://www.ccsq8.com/issues.html
Related Vulnerabilities
CVE-2019-12418 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2019-14517 Vulnerability in npm package editor.md
CVE-2020-28277 Vulnerability in maven package org.webjars.npm:dset
CVE-2020-4075 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-43422 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-utilities