Updated xmlgraphics-commons packages fix a security vulnerability
Publication date: 18 Mar 2021Modification date: 18 Mar 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2020-11988
Description
The Apache XML Graphics Commons library is vulnerable to SSRF via the XMPParser that allow an attacker to cause the underlying server to make arbitrary GET requests (CVE-2020-11988).
References
SRPMS
8/core
- xmlgraphics-commons-2.6-1.mga8
7/core
- xmlgraphics-commons-2.6-1.mga7