Back

CRITICAL

batik: information disclosure when deserializing

Published May 24, 2018

Description

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published May 24, 2018
Updated Sep 16, 2024
Reserved Mar 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 23, 2018
GHSA-25GW-4PCC-45CF