
Cloud Vulnerability DB
A community-led vulnerabilities database
Apache Batik 1.13 was found to be vulnerable to server-side request forgery (SSRF) due to improper input validation by the NodePickerPanel component. The vulnerability was assigned CVE-2020-11987 and was publicly disclosed on February 24, 2021. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests (NVD, Apache Security).
The vulnerability has a CVSS v3.1 Base Score of 8.2 (HIGH) with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N. This indicates the vulnerability is network accessible, requires low attack complexity, needs no privileges or user interaction, and can result in high confidentiality impact and low integrity impact (NVD).
A successful exploitation of this vulnerability could allow attackers to cause the server to make arbitrary GET requests, potentially leading to information disclosure and server-side request forgery attacks. The vulnerability affects the confidentiality and integrity of the system, with high and low impacts respectively (NVD).
The vulnerability is remotely exploitable without requiring authentication or user interaction. The attack complexity is rated as low, making it relatively straightforward for attackers to exploit (NVD).
The vulnerability was fixed in Apache Batik version 1.14, released on January 20, 2021. Users are strongly recommended to upgrade to version 1.14 or later to address this security issue (Apache Security).
Multiple organizations and vendors responded to this vulnerability by incorporating fixes in their products and issuing advisories, including Oracle, Debian, Fedora, and Gentoo (Oracle CPU, Debian, Fedora, Gentoo).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."