CVE Published: 24/02/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: apache |
Vendor: n/a |
Product: Apache Batik Status : PUBLISHED
CVE-2020-11987 Description
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.