Описание
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
A flaw was found in Apache Batik, where a malicious SVG can probe user profile data and send it directly as parameter to a URL. This issue can allow an attacker to conduct SSRF attacks.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat build of Apache Camel for Spring Boot 3 | batik | Affected | ||
Red Hat build of OptaPlanner 8 | batik | Not affected | ||
Red Hat Data Grid 8 | batik | Not affected | ||
Red Hat Decision Manager 7 | batik | Affected | ||
Red Hat Enterprise Linux 6 | batik | Out of support scope | ||
Red Hat Enterprise Linux 6 | fop | Out of support scope | ||
Red Hat Enterprise Linux 7 | batik | Out of support scope | ||
Red Hat Enterprise Linux 8 | batik | Will not fix | ||
Red Hat Fuse 7 | batik | Out of support scope | ||
Red Hat Integration Camel K 1 | batik | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Fo ...
Apache Batik information disclosure vulnerability
Уязвимость библиотеки для работы с SVG-изображениями Apache Batik, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю осуществить SSRF-атаку
EPSS
6.5 Medium
CVSS3