Lucene search

K
osvGoogleOSV:GHSA-H3WV-47XM-4MG6
HistoryOct 19, 2018 - 4:51 p.m.

Server Side Request Forgery in svgSalamander

2018-10-1916:51:25
Google
osv.dev
7

0.004 Low

EPSS

Percentile

74.3%

The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.

CPENameOperatorVersion
com.kitfox.svg:svg-salamandereq1.0