Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfw6-mmmp-87xm

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Input Validation in Apache Batik

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

Пакеты

Наименование

org.apache.xmlgraphics:batik

maven
Затронутые версииВерсия исправления

>= 1.0, < 1.8

1.8

EPSS

Процентиль: 97%
0.16564
Средний

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

redhat
около 14 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

nvd
больше 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

debian
больше 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) ...

EPSS

Процентиль: 97%
0.16564
Средний

Дефекты

CWE-20