VDB

GCVE-110-MAGEIA-2021-168

GCVE-110-MAGEIA-2021-168
Advisory Published
Vulnetix · Advisory published April 2, 2021
A flaw was found in the Apache Batik library, where it is vulnerable to a Server-Side Request Forgery attack (SSRF) via "xlink:href" attributes. This flaw allows an attacker to cause the underlying server to make arbitrary GET requests. The highest threat from this vulnerability is to system integrity (CVE-2019-17566). The Apache Batik library is vulnerable to SSRF via the NodePickerPanel that allow an attacker to cause the underlying server to make arbitrary GET requests (CVE-2020-11987).

Affected Products

VendorProductVersionsPlatforms
Mageiabatik0 (affected), 1.13-1.3.mga7 (unaffected), 1.13-1.3.mga7 (unaffected), 0 (affected)
Mageiazoneminder1.34.22-1.1.mga8.tainted (unaffected), 0 (affected)

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›