Apache XML Graphics Batik: Information disclosure vulnerability
Published Aug 22, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.88%
Description
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
Affected products
-
Affected
- 1.16
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache XML Graphics Batik | unaffected | Affected
|
Configuration 1
- ≥ 1.0 · ≤ 1.16
Configuration 2
- 10.0
No data.
RHINT Camel-Springboot 4.0.0
batik
Fixed · RHSA-2023:5441
RHPAM 7.13.5 async
batik
Fixed · RHSA-2024:1353
Red Hat Data Grid 8
batik
Not affected
Red Hat Decision Manager 7
batik
Affected
Red Hat Enterprise Linux 6
batik
Out of support scope
Red Hat Enterprise Linux 6
fop
Out of support scope
Red Hat Enterprise Linux 7
batik
Out of support scope
Red Hat Enterprise Linux 8
batik
Will not fix
Red Hat Fuse 7
batik
Out of support scope
Red Hat Integration Camel K 1
batik
Will not fix
Red Hat JBoss Data Grid 7
batik
Not affected
Red Hat JBoss Enterprise Application Platform 7
batik
Not affected
Red Hat JBoss Enterprise Application Platform 8
batik
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
batik
Not affected
Red Hat JBoss Fuse 6
batik
Out of support scope
Red Hat JBoss Fuse Service Works 6
batik
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
batik
Affected
Red Hat build of OptaPlanner 8
batik
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHINT Camel-Springboot 4.0.0 | batik | Fixed | RHSA-2023:5441 |
| RHPAM 7.13.5 async | batik | Fixed | RHSA-2024:1353 |
| Red Hat Data Grid 8 | batik | Not affected | n/a |
| Red Hat Decision Manager 7 | batik | Affected | n/a |
| Red Hat Enterprise Linux 6 | batik | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | fop | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | batik | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | batik | Will not fix | n/a |
| Red Hat Fuse 7 | batik | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | batik | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | batik | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | batik | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | batik | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | batik | Not affected | n/a |
| Red Hat JBoss Fuse 6 | batik | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | batik | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | batik | Affected | n/a |
| Red Hat build of OptaPlanner 8 | batik | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://www.openwall.com/lists/oss-security/2023/08/22/3 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/5 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-44730 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2233899 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2182 Advisory
- https://github.com/advisories/GHSA-2474-2566-3qxp Advisory
- https://github.com/apache/xmlgraphics-batik/commit/64658ccda90deaf6bf5f5b4d4a2ec365fe648bfa
- https://github.com/apache/xmlgraphics-batik/commit/f9ae69233eadfbd392a4a08a55618f97343b467c
- https://issues.apache.org/jira/browse/BATIK-1347
- https://lists.apache.org/thread/58m5817jr059f4v1zogh0fngj9pwjyj0 vendor-advisoryMailing ListVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html Mailing List
- https://nvd.nist.gov/vuln/detail/CVE-2022-44730
- https://security.gentoo.org/glsa/202401-11
- https://www.cve.org/CVERecord?id=CVE-2022-44730
- https://xmlgraphics.apache.org/security.html Vendor Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub