Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11988

Опубликовано: 24 фев. 2021
Источник: nvd
CVSS3: 8.2
CVSS2: 6.4
EPSS Низкий

Описание

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:xmlgraphics_commons:*:*:*:*:*:*:*:*
Версия до 2.4 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.0018
Низкий

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.2
ubuntu
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
redhat
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

CVSS3: 8.2
debian
почти 5 лет назад

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-sid ...

suse-cvrf
больше 3 лет назад

Security update for xmlgraphics-commons

CVSS3: 8.2
github
почти 4 года назад

Server-side request forgery (SSRF) in Apache XmlGraphics Commons

EPSS

Процентиль: 40%
0.0018
Низкий

8.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20