Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2023-3815 Vulnerability in maven package com.ruoyi:ruoyi
CVE-2022-45143 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2023-26487 Vulnerability in npm package vega-functions
CVE-2020-6449 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-20218 Vulnerability in maven package io.fabric8:kubernetes-client