Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2022-2218 Vulnerability in maven package org.webjars.npm:parse-url
CVE-2015-6420 Vulnerability in maven package commons-collections:commons-collections
CVE-2017-16116 Vulnerability in maven package org.webjars.npm:string
CVE-2023-6134 Vulnerability in maven package org.keycloak:keycloak-services