Back to search
CVE-2017-5617
Published: Mar 16, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20170129 Re: SSRF issue in the svgsalamander library
mailing-list
x_refsource_MLIST
95871
vdb-entry
x_refsource_BID
DSA-3781
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20170127 SSRF issue in the svgsalamander library
mailing-list
x_refsource_MLIST
https://github.com/blackears/svgSalamander/issues/11
x_refsource_CONFIRM
FEDORA-2019-3cbce64a64
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-735d3953e8
vendor-advisory
x_refsource_FEDORA
GLSA-202003-11
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now