Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-debug-jdk15on
CVE-2022-41854 Vulnerability in maven package org.yaml:snakeyaml
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2023-50164 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-4245 Vulnerability in maven package org.webjars.npm:rfc6902