PT-2021-5808 · Apache+3 · Apache Xmlgraphics Commons+3
Published
2021-02-24
·
Updated
2025-05-22
·
CVE-2020-11988
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache XmlGraphics Commons versions 2.4 and earlier
Description
The issue is related to server-side request forgery caused by improper input validation by the XMPParser. An attacker could exploit this by using a specially-crafted argument to cause the underlying server to make arbitrary GET requests. This could potentially allow a remote attacker to access confidential data and compromise its integrity.
Recommendations
For Apache XmlGraphics Commons versions 2.4 and earlier, users should upgrade to version 2.6 or later to resolve the issue. As a temporary workaround, consider restricting input validation to prevent exploitation until a patch is applied.
Fix
SSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Apache Xmlgraphics Commons
Astra Linux
Suse