Advisories ยป MGASA-2021-0168

Updated batik packages fix security vulnerabilities

Publication date: 02 Apr 2021
Modification date: 02 Apr 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-17566 , CVE-2020-11987

Description

A flaw was found in the Apache Batik library, where it is vulnerable to a
Server-Side Request Forgery attack (SSRF) via "xlink:href" attributes. This
flaw allows an attacker to cause the underlying server to make arbitrary GET
requests. The highest threat from this vulnerability is to system integrity
(CVE-2019-17566).

The Apache Batik library is vulnerable to SSRF via the NodePickerPanel that
allow an attacker to cause the underlying server to make arbitrary GET requests
(CVE-2020-11987).
                

References

SRPMS

7/core