Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3405
HistoryFeb 02, 2017 - 7:38 a.m.

Server Side Request Forgery (SSRF)

2017-02-0207:38:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.004 Low

EPSS

Percentile

74.3%

svg-salamander is vulnerable to server side request forgery (SSRF) attacks. The vulnerability exists because svg-salamander does not restrict the schemes supported in the SVG file. An attacker can exploit this vulnerability by supplying a SVG file with file://, jar://, or other application specific scheme to conduct the attack.

CPENameOperatorVersion
svg salamandereq0.1.19
svg salamandereq1.0