Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.xmlgraphics:batik(Maven) | 1.14 | 1.15 | N/A |
| org.apache.xmlgraphics:batik-bridge(Maven) | 1.14 | 1.15 | N/A |
CVSS Metrics