Advertisement






Apache XML Graphics FOP 2.1 Information Disclosure

CVE Category Price Severity
CVE-2017-5661 CWE-200 Not specified Medium
Author Risk Exploitation Type Date
Unknown High Remote 2017-04-19
CPE
cpe:cpe:/a:apache:xmlgraphics_fop:2.1
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017040120

Below is a copy:

Apache XML Graphics FOP 2.1 Information DisclosureCVE-2017-5661:
        Apache XML Graphics FOP information disclosure vulnerability

Severity:
        Medium

Vendor:
        The Apache Software Foundation

Versions Affected:
        FOP 1.0 - 2.1

Description:
        Files lying on the filesystem of the server which uses batik can
        be revealed to arbitrary users who send maliciously formed SVG
        files. The file types that can be shown depend on the user context
        in which the exploitable application is running. If the user is root
        a full compromise of the server--including confidential or sensitive
        files--would be possible.

        XXE can also be used to attack the availability of the server
        via denial of service as the references within a xml document
        can trivially trigger an amplification attack.

Mitigation:
        Users should upgrade to FOP 2.2+

Credit:
        This issue was independently reported by Pierre Ernst at Salesforce.

References:
        http://xmlgraphics.apache.org/security.html

The Apache XML Graphics team.


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum