Back to search
CVE-2020-11987
Published: Feb 24, 2021
Modified: Nov 3, 2025
PUBLISHED
Description
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
| Vendor | Product | Versions |
|---|---|---|
n/a | Apache Batik | affected Apache Batik 1.13 |
References
FEDORA-2021-65ff5f10e2
vendor-advisory
FEDORA-2021-33a1b73e48
vendor-advisory
GLSA-202401-11
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now