Candidate: CVE-2020-11988 PublicDate: 2021-02-24 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11988 https://xmlgraphics.apache.org/security.html Description: Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N [8.2 HIGH] Patches_xmlgraphics-commons: upstream_xmlgraphics-commons: needs-triage precise/esm_xmlgraphics-commons: DNE trusty_xmlgraphics-commons: ignored (out of standard support) trusty/esm_xmlgraphics-commons: DNE xenial_xmlgraphics-commons: ignored (end of standard support, was needs-triage) bionic_xmlgraphics-commons: needs-triage focal_xmlgraphics-commons: needs-triage groovy_xmlgraphics-commons: ignored (reached end-of-life) hirsute_xmlgraphics-commons: ignored (reached end-of-life) impish_xmlgraphics-commons: needs-triage jammy_xmlgraphics-commons: needs-triage devel_xmlgraphics-commons: needs-triage