Description
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
Remediation
References
https://www.ccsq8.com/issues.html
Related Vulnerabilities
CVE-2022-41879 Vulnerability in npm package parse-server
CVE-2016-10591 Vulnerability in npm package prince
CVE-2020-11987 Vulnerability in maven package org.apache.xmlgraphics:batik-svgbrowser
CVE-2022-23944 Vulnerability in maven package org.apache.shenyu:shenyu-common
CVE-2021-20293 Vulnerability in maven package org.jboss.resteasy:resteasy-core