All errata/sisyphus/ALT-PU-2021-4963-1
ALT-PU-2021-4963-1

Package update batik in branch sisyphus

Version1.14-alt1_1jpp8
Published2021-06-12
Max severityHIGH
Severity:

Closed issues (2)

CVE-2020-11987
HIGH8.2

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Published: 2021-02-24Modified: 2025-11-03
CVSS 2.0MEDIUM 6.4
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:N
CVSS 3.xHIGH 8.2
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
References
GHSA-2h63-qp69-fwvw
HIGH8.2

Server-side request forgery (SSRF) in Apache Batik

Published: 2022-01-06Modified: 2022-02-09
CVSS 3.xHIGH 8.2
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
References