Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2022-25845 Vulnerability in maven package com.alibaba:fastjson
CVE-2021-29624 Vulnerability in npm package fastify-csrf
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-engine
CVE-2023-38507 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2022-43484 Vulnerability in maven package org.terasoluna.gfw:terasoluna-gfw-common