CVE List

CVE-2020-11987

Moderate 5.3

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Published February 24, 2021.

Affected software

Get alerts for Apache Batik

Reference links