Apache Batik prior to 1.16 allows RCE via scripting
Published Oct 25, 2022
7.5
HIGHCVSS 3.1
EPSS 2.69%
Description
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
Affected products
-
Affected
- ≥ Batik, ≤ 1.15
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache XML Graphics | unknown | Affected
|
Configuration 2
- 10.0
- 11.0
No data.
RHINT Camel-Springboot 3.20.1
batik
Fixed · RHSA-2023:2100
Red Hat Fuse 7.12
batik
Fixed · RHSA-2023:3954
Red Hat Decision Manager 7
batik
Out of support scope
Red Hat Integration Camel K 1
batik
Will not fix
Red Hat Integration Camel Quarkus 2
batik
Will not fix
Red Hat JBoss Data Grid 7
batik
Out of support scope
Red Hat Process Automation 7
batik
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| RHINT Camel-Springboot 3.20.1 | batik | Fixed | RHSA-2023:2100 |
| Red Hat Fuse 7.12 | batik | Fixed | RHSA-2023:3954 |
| Red Hat Decision Manager 7 | batik | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | batik | Will not fix | n/a |
| Red Hat Integration Camel Quarkus 2 | batik | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | batik | Out of support scope | n/a |
| Red Hat Process Automation 7 | batik | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://www.openwall.com/lists/oss-security/2022/10/25/3 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-42890 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2182183 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7161 Advisory
- https://github.com/advisories/GHSA-rwqr-m72q-v6cm Advisory
- https://github.com/apache/xmlgraphics-batik/commit/401aa8595f52d085d40ff5b6b4ac0dd372423082
- https://github.com/apache/xmlgraphics-batik/commit/52f7a1ad6e3110ec295a35ffc94410eef085707a
- https://github.com/apache/xmlgraphics-batik/commit/eada57c716a2757579d53017f8b2aeadaad20edd
- https://issues.apache.org/jira/browse/BATIK-1345
- https://lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwly Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00038.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-42890
- https://security.gentoo.org/glsa/202401-11 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2022-42890
- https://www.debian.org/security/2022/dsa-5264 vendor-advisoryThird Party Advisory
- https://xmlgraphics.apache.org/security.html
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub