First published: Thu Nov 17 2022(Updated: )
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xuxueli xxl-job | <=2.3.1 | |
maven/com.xuxueli:xxl-job-core | <2.3.1 | 2.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43183 is a vulnerability in XXL-Job before v2.3.1 that allows Server-Side Request Forgery (SSRF) attacks via the component /admin/controller/JobLogController.java.
CVE-2022-43183 has a severity score of 8.8 (high severity).
The affected software is XXL-Job with versions up to and including 2.3.1.
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests from the server to other internal or external resources.
You can find more information about CVE-2022-43183 at the following link: [link](https://github.com/xuxueli/xxl-job/issues/3002)