Описание
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
Ссылки
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:kitfox:svg_salamander:-:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01078
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 7.4
ubuntu
почти 9 лет назад
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
CVSS3: 7.4
debian
почти 9 лет назад
The SVG Salamander (aka svgSalamander) library, when used in a web app ...
EPSS
Процентиль: 77%
0.01078
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-918