Description
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3002
Related Vulnerabilities
CVE-2022-39218 Vulnerability in npm package @fastly/js-compute
CVE-2020-36186 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-11050 Vulnerability in maven package org.java-websocket:java-websocket
CVE-2011-0013 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-7961 Vulnerability in maven package com.liferay.portal:com.liferay.portal.impl