QID 981195
QID 981195: Java (maven) Security Update for com.xuxueli:xxl-conf (GHSA-8j39-fgfp-vxh8)
An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8j39-fgfp-vxh8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-8j39-fgfp-vxh8 -
github.com/advisories/GHSA-8j39-fgfp-vxh8
CVEs related to QID 981195
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8j39-fgfp-vxh8 | com.xuxueli:xxl-conf |
|