The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.kitfox.svg:svg-salamander(Maven) | 0 | 1.1.2 | N/A |
CVSS Metrics