Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2022-46164 Vulnerability in npm package nodebb
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-service
CVE-2021-46708 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2020-7753 Vulnerability in maven package org.webjars.npm:trim
CVE-2023-41578 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent