Back

HIGH

Apache Batik prior to 1.16 allows RCE via scripting

Published Oct 25, 2022

Description

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Oct 25, 2022
Updated Aug 3, 2024
Reserved Oct 12, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 25, 2022
Bugzilla 2182183

ENISA EUVD

Assigner apache
Published Oct 25, 2022
Updated Aug 3, 2024