QID 981072
QID 981072: Java (maven) Security Update for com.kitfox.svg:svg-salamander (GHSA-h3wv-47xm-4mg6)
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h3wv-47xm-4mg6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h3wv-47xm-4mg6 -
github.com/advisories/GHSA-h3wv-47xm-4mg6
CVEs related to QID 981072
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h3wv-47xm-4mg6 | com.kitfox.svg:svg-salamander |
|