A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://fortiguard.com/zeroday/FG-VD-19-115 | third party advisory |
https://git.drupalcode.org/project/svg_sanitizer/commit/e1b0666 | third party advisory patch |