CVE-2020-11988
published 2021-02-24CVE-2020-11988: Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a…
PriorityP358high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
6.65%
93.2th percentile
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xmlgraphics_commons | <= 2.4 | — |
| debian | xmlgraphics-commons | < xmlgraphics-commons 2.4-2 (bookworm) | xmlgraphics-commons 2.4-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv8.2HIGH
vendor_debian8.2HIGH
vendor_oracle8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Server-side request forgery (SSRF) in Apache XmlGraphics Commons
osv·2022-02-09
CVE-2020-11988 [HIGH] Server-side request forgery (SSRF) in Apache XmlGraphics Commons
Server-side request forgery (SSRF) in Apache XmlGraphics Commons
Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
GHSA
Server-side request forgery (SSRF) in Apache XmlGraphics Commons
ghsa·2022-02-09
CVE-2020-11988 [HIGH] CWE-20 Server-side request forgery (SSRF) in Apache XmlGraphics Commons
Server-side request forgery (SSRF) in Apache XmlGraphics Commons
Apache XmlGraphics Commons 2.4 is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
OSV
CVE-2020-11988: Apache XmlGraphics Commons 2
osv·2021-02-24·CVSS 8.2
CVE-2020-11988 [HIGH] CVE-2020-11988: Apache XmlGraphics Commons 2
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Platform (Apache XmlGraphics Commons) — CVE-2020-11988
vendor_oracle·2025-10-15·CVSS 8.2
CVE-2020-11988 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Platform (Apache XmlGraphics Commons) — CVE-2020-11988
Oracle Oracle Financial Services Applications Risk Matrix: Platform (Apache XmlGraphics Commons) vulnerability
CVE: CVE-2020-11988
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Analytics Risk Matrix: BI FNDN (Apache XmlGraphics Commons) — CVE-2020-11988
vendor_oracle·2023-07-15·CVSS 8.2
CVE-2020-11988 [HIGH] Oracle Oracle Analytics Risk Matrix: BI FNDN (Apache XmlGraphics Commons) — CVE-2020-11988
Oracle Oracle Analytics Risk Matrix: BI FNDN (Apache XmlGraphics Commons) vulnerability
CVE: CVE-2020-11988
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache XML Graphics Commons) — CVE-2020-11988
vendor_oracle·2023-04-15·CVSS 8.2
CVE-2020-11988 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache XML Graphics Commons) — CVE-2020-11988
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache XML Graphics Commons) vulnerability
CVE: CVE-2020-11988
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
xmlgraphics-commons: SSRF due to improper input validation by the XMPParser
vendor_redhat·2021-02-24·CVSS 8.2
CVE-2020-11988 [HIGH] CWE-918 xmlgraphics-commons: SSRF due to improper input validation by the XMPParser
xmlgraphics-commons: SSRF due to improper input validation by the XMPParser
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
Statement: This flaw does not affect xmlgraphics-commons as shipped with Red Hat Enterprise Linux 8. It is out of support scope for Red Hat Enterprise Linux 6 and 7. To learn more about support scope for Red Hat Enterprise Linux, please see https://access.redhat.com/support/policy/updates/errata/ .
Mitigation: Mitigation for this issue is either not available or the currently available opti
Debian
CVE-2020-11988: xmlgraphics-commons - Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request ...
vendor_debian·2020·CVSS 8.2
CVE-2020-11988 [HIGH] CVE-2020-11988: xmlgraphics-commons - Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request ...
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
Scope: local
bookworm: resolved (fixed in 2.4-2)
bullseye: resolved (fixed in 2.4-2~deb11u1)
forky: resolved (fixed in 2.4-2)
sid: resolved (fixed in 2.4-2)
trixie: resolved (fixed in 2.4-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/ra8f4d6ae402ec020ee3e8c28632c91be131c4d8b4c9c6756a179b12b%40%3Cdev.jmeter.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22HESSYU7T4D6GGENUVEX3X3H6FGBECH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JP4XA56DA3BFNRBBLBXM6ZAI5RUVFA33/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://xmlgraphics.apache.org/security.htmlhttps://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05%40%3Cdev.poi.apache.org%3Ehttps://lists.apache.org/thread.html/ra8f4d6ae402ec020ee3e8c28632c91be131c4d8b4c9c6756a179b12b%40%3Cdev.jmeter.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22HESSYU7T4D6GGENUVEX3X3H6FGBECH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JP4XA56DA3BFNRBBLBXM6ZAI5RUVFA33/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://xmlgraphics.apache.org/security.html
2021-02-24
Published