Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2h63-qp69-fwvw

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Server-side request forgery (SSRF) in Apache Batik

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Ссылки

Пакеты

Наименование

org.apache.xmlgraphics:batik-svgbrowser

maven
Затронутые версииВерсия исправления

< 1.14

1.14

EPSS

Процентиль: 80%
0.01358
Низкий

8.2 High

CVSS3

Дефекты

CWE-20
CWE-918

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 5 лет назад

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 8.2
redhat
почти 5 лет назад

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 8.2
nvd
почти 5 лет назад

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 8.2
debian
почти 5 лет назад

Apache Batik 1.13 is vulnerable to server-side request forgery, caused ...

suse-cvrf
почти 2 года назад

Security update for xmlgraphics-batik

EPSS

Процентиль: 80%
0.01358
Низкий

8.2 High

CVSS3

Дефекты

CWE-20
CWE-918