An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.
{
"github_reviewed_at": "2020-06-16T21:25:45Z",
"nvd_published_at": null,
"github_reviewed": true,
"cwe_ids": [
"CWE-22"
],
"severity": "HIGH"
}