Lucene search

K
osvGoogleOSV:GHSA-2H63-QP69-FWVW
HistoryJan 06, 2022 - 8:35 p.m.

Server-side request forgery (SSRF) in Apache Batik

2022-01-0620:35:54
Google
osv.dev
160
apache
batik
ssrf
vulnerability
nodepickerpanel
input validation
get requests
software

EPSS

0.007

Percentile

80.7%

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

References