Lucene search

K
osvGoogleOSV:GHSA-CMX4-P4V5-HMR5
HistoryFeb 09, 2022 - 12:46 a.m.

Server-side request forgery (SSRF) in Apache Batik

2022-02-0900:46:46
Google
osv.dev
49
apache batik
vulnerability
ssrf
input validation
get requests

EPSS

0.002

Percentile

53.4%

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the โ€œxlink:hrefโ€ attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

References