Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2021-37694 Vulnerability in npm package @asyncapi/java-spring-cloud-stream-template
CVE-2023-48711 Vulnerability in npm package google-translate-api-browser
CVE-2021-23327 Vulnerability in npm package apexcharts
CVE-2022-24901 Vulnerability in npm package parse-server
CVE-2022-35948 Vulnerability in maven package org.webjars.npm:undici