PT-2021-5808 · Apache+3 · Apache Xmlgraphics Commons+3

Published

2021-02-24

·

Updated

2025-05-22

·

CVE-2020-11988

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache XmlGraphics Commons versions 2.4 and earlier
Description The issue is related to server-side request forgery caused by improper input validation by the XMPParser. An attacker could exploit this by using a specially-crafted argument to cause the underlying server to make arbitrary GET requests. This could potentially allow a remote attacker to access confidential data and compromise its integrity.
Recommendations For Apache XmlGraphics Commons versions 2.4 and earlier, users should upgrade to version 2.6 or later to resolve the issue. As a temporary workaround, consider restricting input validation to prevent exploitation until a patch is applied.

Fix

SSRF

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6398
BDU:2022-00276
CVE-2020-11988
GHSA-FMJ2-7WX8-QJ4V
MGASA-2021-0144
OESA-2022-1649
OPENSUSE-SU-2024:12403-1
SUSE-SU-2022:3550-1
SUSE-SU-2022_3550-1

Affected Products

Alt Linux
Apache Xmlgraphics Commons
Astra Linux
Suse