CVE-2020-23811: Infoleak
Published Sep 3, 2020
·Updated
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
Affected Software
2 affected components
maven/com.xuxueli:xxl-job<=2.2.0
Xuxueli xxl-job=2.2.0
Event History
Sep 3, 2020
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
Description
May 24, 2022
Advisory Published
05:27 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2020-23811.
2
What is the severity of CVE-2020-23811?
The severity of CVE-2020-23811 is high with a severity value of 7.
3
How does CVE-2020-23811 impact xxl-job 2.2.0?
CVE-2020-23811 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java in xxl-job 2.2.0.
4
What is the affected software version for CVE-2020-23811?
The affected software version is xxl-job 2.2.0.
5
How can CVE-2020-23811 be fixed?
To fix CVE-2020-23811, it is recommended to update xxl-job to a version that addresses the vulnerability.