{"id":"GHSA-h3wv-47xm-4mg6","summary":"Server Side Request Forgery in svgSalamander","details":"The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.","aliases":["CVE-2017-5617"],"modified":"2024-02-16T05:52:46.486022Z","published":"2018-10-19T16:51:25Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:38:36Z","nvd_published_at":null,"cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5617"},{"type":"WEB","url":"https://github.com/blackears/svgSalamander/issues/11"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h3wv-47xm-4mg6"},{"type":"PACKAGE","url":"https://github.com/blackears/svgSalamander"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3V7RIIO3HO4RNDBN2PARLIDAL3RPV2OX"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UPUOI6NCEB6H6YHKN7M4V3CAQD63NXAU"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202003-11"},{"type":"WEB","url":"http://www.debian.org/security/2017/dsa-3781"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2017/01/27/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2017/01/29/2"},{"type":"WEB","url":"http://www.securityfocus.com/bid/95871"}],"affected":[{"package":{"name":"com.kitfox.svg:svg-salamander","ecosystem":"Maven","purl":"pkg:maven/com.kitfox.svg/svg-salamander"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.2"}]}],"versions":["1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-h3wv-47xm-4mg6/GHSA-h3wv-47xm-4mg6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"}]}