ZeroHour

CVE-2020-11988

CVSS 3.1
8.2 high
EPSS
7%p93
Published
()
Modified
Description

Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.

Vendors
apachefedoraproject
Products
xmlgraphics commons, fedora
Weakness
CWE-20, CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.