Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
References
Configurations
History
No history.
Information
Published : 2021-02-24 18:15
Updated : 2023-11-07 03:15
NVD link : CVE-2020-11988
Mitre link : CVE-2020-11988
CVE.ORG link : CVE-2020-11988
JSON object : View
Products Affected
apache
- xmlgraphics_commons
fedoraproject
- fedora