Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2014-7192 Vulnerability in npm package syntax-error
CVE-2021-29620 Vulnerability in maven package com.epam.reportportal:service-api
CVE-2022-39312 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2022-1295 Vulnerability in npm package fullpage.js
CVE-2023-34610 Vulnerability in maven package com.cedarsoftware:json-io