Количество 9
Количество 9
CVE-2019-17566
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
CVE-2019-17566
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
CVE-2019-17566
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
CVE-2019-17566
Apache Batik is vulnerable to server-side request forgery, caused by i ...
openSUSE-SU-2020:0851-1
Security update for xmlgraphics-batik
SUSE-SU-2020:1800-1
Security update for xmlgraphics-batik
GHSA-cmx4-p4v5-hmr5
Server-side request forgery (SSRF) in Apache Batik
BDU:2021-01018
Уязвимость библиотеки для работы с SVG-изображениями Apache Batik, связанная с некорректной обработкой данных в атрибутах «xlink: href», позволяющая нарушителю осуществлять CSRF-атаки
SUSE-SU-2024:0777-1
Security update for xmlgraphics-batik
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-17566 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
CVE-2019-17566 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
CVE-2019-17566 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
CVE-2019-17566 Apache Batik is vulnerable to server-side request forgery, caused by i ... | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
openSUSE-SU-2020:0851-1 Security update for xmlgraphics-batik | 1% Низкий | больше 5 лет назад | ||
SUSE-SU-2020:1800-1 Security update for xmlgraphics-batik | 1% Низкий | больше 5 лет назад | ||
GHSA-cmx4-p4v5-hmr5 Server-side request forgery (SSRF) in Apache Batik | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
BDU:2021-01018 Уязвимость библиотеки для работы с SVG-изображениями Apache Batik, связанная с некорректной обработкой данных в атрибутах «xlink: href», позволяющая нарушителю осуществлять CSRF-атаки | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
SUSE-SU-2024:0777-1 Security update for xmlgraphics-batik | почти 2 года назад |
Уязвимостей на страницу