CVE-2020-11987: Server-Side Request Forgery (SSRF)
(updated )
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel
. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
References
Detect and mitigate CVE-2020-11987 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →