CVE-2020-11988
24.02.2021, 18:15
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | xmlgraphics_commons | 𝑥 ≤ 2.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| xmlgraphics-batik |
| ||||||||||||||||||||
| xmlgraphics-batik-css |
| ||||||||||||||||||||
| xmlgraphics-commons |
|
Common Weakness Enumeration
References