batik: SSRF via "xlink:href"
Published Nov 12, 2020
7.5
HIGHCVSS 3.1
EPSS 10.87%
Description
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected products
- Vendor n/a Product Apache Batik Defaultn/a
- Version Apache Batik 1.12 and olderStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache Batik | n/a |
|
Configuration 2
- 11.1.2.4.0
- 5.5.0.0.0
- 5.9.0.0.0
- 12.2.1.3.0
- 12.2.1.4.0
- 3.9m0p2
- ≥ 6.3.0 · ≤ 6.3.1
- 12.0.0.3.0
- 11.1.1.7.0
- ≥ 8.0.6 · ≤ 8.1.0
- 12.2.1.4.0
- 5.5
- 5.6
- 11.1.2.4
- 11.2.5.0
- ≥ 17.1 · ≤ 17.3
- < 9.2.4.0
- 9.2.4.2
- 15.0.3
- 15.0
- 16.0
- 19.5
- 14.1
- 14.1
No data.
RHDM 7.9.0
batik
Fixed · RHSA-2020:4960
RHPAM 7.9.0
batik
Fixed · RHSA-2020:4961
Red Hat Fuse 7.8.0
batik
Fixed · RHSA-2020:5568
Red Hat BPM Suite 6
batik
Out of support scope
Red Hat Enterprise Linux 6
batik
Out of support scope
Red Hat Enterprise Linux 7
batik
Will not fix
Red Hat Enterprise Linux 8
eclipse
Not affected
Red Hat JBoss BRMS 6
batik
Out of support scope
Red Hat JBoss Fuse 6
batik
Out of support scope
Red Hat JBoss Fuse Service Works 6
batik
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| RHDM 7.9.0 | batik | Fixed | RHSA-2020:4960 |
| RHPAM 7.9.0 | batik | Fixed | RHSA-2020:4961 |
| Red Hat Fuse 7.8.0 | batik | Fixed | RHSA-2020:5568 |
| Red Hat BPM Suite 6 | batik | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | batik | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | batik | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | eclipse | Not affected | n/a |
| Red Hat JBoss BRMS 6 | batik | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | batik | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | batik | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- https://access.redhat.com/security/cve/CVE-2019-17566 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1848617 Issue Tracking
- https://github.com/advisories/GHSA-cmx4-p4v5-hmr5 Advisory
- https://github.com/apache/xmlgraphics-batik/commit/bc6078ca949039e2076cd08b4cb169c84c1179b1
- https://issues.apache.org/jira/browse/BATIK-1276
- https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171@%3Ccommits.myfaces.apache.org%3E
- https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509@%3Ccommits.myfaces.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2019-17566
- https://security.gentoo.org/glsa/202401-11 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-17566
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://xmlgraphics.apache.org/security.html Vendor Advisory
Change history (0)
No recorded changes yet.