[jira] [Updated] (XGC-122) Dont load DTDs in XMP

2021-02-24 Thread Simon Steiner (Jira)
[ https://issues.apache.org/jira/browse/XGC-122?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Simon Steiner updated XGC-122: -- Description: XMPParser should not load external dtds   CVE-2020-11988 was:XMPParser should not load e

[CVE-2020-11988] Apache XML Graphics Commons SSRF vulnerability

2021-02-24 Thread Simon Steiner
CVE-2020-11988: Apache XML Graphics Commons SSRF vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: XML Graphics Commons 2.4 and earlier Description: The Apache XML Graphics Commons library is vulnerable to SSRF via t