Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17566

Опубликовано: 15 июн. 2020
Источник: redhat
CVSS3: 7.5

Описание

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

A flaw was found in the Apache Batik library, where it is vulnerable to a Server-Side Request Forgery attack (SSRF) via "xlink:href" attributes. This flaw allows an attacker to cause the underlying server to make arbitrary GET requests. The highest threat from this vulnerability is to system integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6batikOut of support scope
Red Hat CodeReady Studio 12batikNot affected
Red Hat Enterprise Linux 6batikOut of support scope
Red Hat Enterprise Linux 7batikWill not fix
Red Hat Enterprise Linux 8eclipseNot affected
Red Hat JBoss BRMS 6batikOut of support scope
Red Hat JBoss Fuse 6batikOut of support scope
Red Hat JBoss Fuse Service Works 6batikOut of support scope
Red Hat Fuse 7.8.0batikFixedRHSA-2020:556816.12.2020
RHDM 7.9.0batikFixedRHSA-2020:496005.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 7.5
nvd
около 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS3: 7.5
debian
около 5 лет назад

Apache Batik is vulnerable to server-side request forgery, caused by i ...

suse-cvrf
больше 5 лет назад

Security update for xmlgraphics-batik

suse-cvrf
больше 5 лет назад

Security update for xmlgraphics-batik

7.5 High

CVSS3