CVE-2022-43183: SSRF
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
Other sources
XXL-Job before v2.4.0 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.xuxueli:xxl-job-coreto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Frequently Asked Questions
What is CVE-2022-43183?
CVE-2022-43183 is a vulnerability in XXL-Job before v2.3.1 that allows Server-Side Request Forgery (SSRF) attacks via the component /admin/controller/JobLogController.java.
How severe is CVE-2022-43183?
CVE-2022-43183 has a severity score of 8.8 (high severity).
What is the affected software and version?
The affected software is XXL-Job with versions up to and including 2.3.1.
What is Server-Side Request Forgery (SSRF)?
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests from the server to other internal or external resources.
Where can I find more information about CVE-2022-43183?
You can find more information about CVE-2022-43183 at the following link: [link](https://github.com/xuxueli/xxl-job/issues/3002)