Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xmlgraphics-commons-javadocUpgrade xmlgraphics-commons | Jan 10, 2024 | Feb 24, 2021 |
| Debian | — | Upgrade xmlgraphics-commons | Jul 30, 2024 | Feb 24, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 24, 2021 |
| Suse | — | Upgrade xmlgraphics-commonsUpgrade xmlgraphics-batik-javadocUpgrade xmlgraphics-batik-slideshowUpgrade xmlgraphics-batik-ttf2svgUpgrade xmlgraphics-batik-svgppUpgrade xmlgraphics-batik-demoUpgrade xmlgraphics-batik-cssUpgrade xmlgraphics-batik-squiggleUpgrade xmlgraphics-batikUpgrade xmlgraphics-batik-rasterizer | Aug 9, 2024 | Feb 24, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub