Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmx4-p4v5-hmr5

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Server-side request forgery (SSRF) in Apache Batik

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Пакеты

Наименование

org.apache.xmlgraphics:batik

maven
Затронутые версииВерсия исправления

< 1.13

1.13

EPSS

Процентиль: 74%
0.00815
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 7.5
redhat
больше 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 7.5
nvd
около 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 7.5
debian
около 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by i ...

suse-cvrf
больше 5 лет назад

Security update for xmlgraphics-batik

EPSS

Процентиль: 74%
0.00815
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-918