CVE-2020-11987

🟠 Łataj w tym tygodniu

Podatność w Apache Batik umożliwia atakującemu wykonanie dowolnych żądań GET na serwerze.

CVSS
8.2
EPSS
13.3%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)13.3%
Opublikowano (NVD)2021-02-24 18:15:11 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:55 UTC
Referencje