Lucene search

K
osvGoogleOSV:GHSA-FMJ2-7WX8-QJ4V
HistoryFeb 09, 2022 - 12:45 a.m.

Server-side request forgery (SSRF) in Apache XmlGraphics Commons

2022-02-0900:45:56
Google
osv.dev
54

0.002 Low

EPSS

Percentile

59.3%

Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

References