Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25693
HistoryJun 16, 2020 - 9:19 a.m.

Server-side Request Forgery (SSRF)

2020-06-1609:19:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29

0.002 Low

EPSS

Percentile

53.5%

batik-svgrasterizer is vulnerable to server side request forgery (SSRF). It is possible as it does not prevent an attacker to make malicious GET requests on behalf of the server through the use of xlink:hrefattributes which allows access to internal resources.