| Vulnerability Name: | CVE-2017-5617 (CCN-123585) | ||||||||||||||||||||||||
| Assigned: | 2017-03-16 | ||||||||||||||||||||||||
| Published: | 2017-03-16 | ||||||||||||||||||||||||
| Updated: | 2020-07-08 | ||||||||||||||||||||||||
| Summary: | The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N/E:U/RL:U/RC:R)
5.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-918 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-5617 Source: DEBIAN Type: Third Party Advisory DSA-3781 Source: CCN Type: oss-sec Mailing List, Fri, 27 Jan 2017 10:51:09 +0300 SSRF issue in the svgsalamander library Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20170127 SSRF issue in the svgsalamander library Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20170129 Re: SSRF issue in the svgsalamander library Source: BID Type: Third Party Advisory, VDB Entry 95871 Source: CCN Type: BID-95871 SVG Salamander CVE-2017-5617 Server Side Request Forgery Security Bypass Vulnerability Source: XF Type: UNKNOWN svg-salamander-cve20175617-ssrf(123585) Source: CCN Type: svgSalamander GIT Repository SSRF (Server-Side Request Forgery) is possible [CVE-2017-5617] #11 Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/blackears/svgSalamander/issues/11 Source: FEDORA Type: Third Party Advisory FEDORA-2019-735d3953e8 Source: FEDORA Type: Third Party Advisory FEDORA-2019-3cbce64a64 Source: GENTOO Type: Third Party Advisory GLSA-202003-11 | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||