PT-2022-5346 · Apache+6 · Apache Batik+8

4Ra1N

+2

·

Published

2022-10-25

·

Updated

2024-03-16

·

CVE-2022-41704

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache XML Graphics versions prior to 1.16 Confluence Data Center and Server versions 7.13.0 through 7.19.0, specifically versions prior to 7.19.16
Description A vulnerability in the Apache Batik library for working with SVG images is related to insufficient checking of incoming requests. This issue allows an attacker to run untrusted Java code from an SVG, potentially enabling remote execution of arbitrary Java code. The estimated impact of this issue is high, with potential exposure of assets in the environment susceptible to exploitation, affecting confidentiality.
Recommendations For Apache XML Graphics versions prior to 1.16, update to version 1.16. For Confluence Data Center and Server versions 7.13.0 through 7.19.0, upgrade to a release greater than or equal to 7.19.16. As a temporary workaround, consider restricting the use of SVG images in your environment until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2022-06660
CVE-2022-41704
DLA-3169-1
DSA-5264-1
GHSA-R29W-R9PH-VM76
MGASA-2024-0068
OESA-2023-1050
OESA-2023-1051
OESA-2023-1057
OESA-2023-1060
OPENSUSE-SU-2024:13743-1
OPENSUSE-SU-2024_0808-1
ROSA-SA-2023-2239
SUSE-SU-2024:0777-1
SUSE-SU-2024:0808-1
SUSE-SU-2024_0808-1
USN-6117-1

Affected Products

Apache Batik
Apache Xml Graphics
Astra Linux
Confluence
Jira
Linuxmint
Red Os
Suse
Ubuntu