GHSA-8j39-fgfp-vxh8
HIGHCVE-2018-20094An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.
- Affected
- <= 1.6.0
- Fixed in
- not stated
- Published
- 2018-12-19
- Source
- github