Description
svg2png 4.1.1 allows XSS with resultant SSRF via JavaScript inside an SVG document.
Remediation
References
https://github.com/domenic/svg2png/issues/117
Related Vulnerabilities
CVE-2020-27218 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2020-7789 Vulnerability in npm package node-notifier
CVE-2022-0722 Vulnerability in npm package parse-url
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement
CVE-2022-36890 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework