Description
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
Remediation
References
https://www.ccsq8.com/issues.html
Related Vulnerabilities
CVE-2019-10801 Vulnerability in npm package enpeem
CVE-2023-30530 Vulnerability in maven package org.jenkins-ci.plugins:consul-kv-builder
CVE-2022-39246 Vulnerability in maven package org.matrix.android:matrix-android-sdk2
CVE-2016-6796 Vulnerability in maven package tomcat:jasper
CVE-2017-5648 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core