The Apache Batik library is vulnerable to SSRF via the NodePickerPanel that allow an attacker to cause the underlying server to make arbitrary GET requests (CVE-2020-11987).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2021-0139.json"