Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmj2-7wx8-qj4v

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Server-side request forgery (SSRF) in Apache XmlGraphics Commons

Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Пакеты

Наименование

org.apache.xmlgraphics:xmlgraphics-commons

maven
Затронутые версииВерсия исправления

< 2.6

2.6

EPSS

Процентиль: 40%
0.0018
Низкий

8.2 High

CVSS3

Дефекты

CWE-20
CWE-918

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
redhat
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
nvd
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
debian
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-sid ...

suse-cvrf
больше 3 лет назад

Security update for xmlgraphics-commons

EPSS

Процентиль: 40%
0.0018
Низкий

8.2 High

CVSS3

Дефекты

CWE-20
CWE-918