Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-11988

Опубликовано: 24 фев. 2021
Источник: debian

Описание

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xmlgraphics-commonsfixed2.4-2package
xmlgraphics-commonsfixed2.4-2~deb11u1bullseyepackage
xmlgraphics-commonsfixed2.3-1+deb10u1busterpackage
xmlgraphics-commonsnot-affectedstretchpackage

Примечания

  • https://github.com/apache/xmlgraphics-commons/commit/57393912eb87b994c7fed39ddf30fb778a275183

  • https://issues.apache.org/jira/browse/XGC-122

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
redhat
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
nvd
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

suse-cvrf
больше 3 лет назад

Security update for xmlgraphics-commons

CVSS3: 8.2
github
почти 4 года назад

Server-side request forgery (SSRF) in Apache XmlGraphics Commons