CVE-2017-5617

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
16/03/2017
Last modified:
20/04/2025

Description

The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:kitfox:svg_salamander:-:*:*:*:*:*:*:*