PT-2022-5346 · Apache+6 · Apache Batik+8
4Ra1N
+2
·
Published
2022-10-25
·
Updated
2024-03-16
·
CVE-2022-41704
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache XML Graphics versions prior to 1.16
Confluence Data Center and Server versions 7.13.0 through 7.19.0, specifically versions prior to 7.19.16
Description
A vulnerability in the Apache Batik library for working with SVG images is related to insufficient checking of incoming requests. This issue allows an attacker to run untrusted Java code from an SVG, potentially enabling remote execution of arbitrary Java code. The estimated impact of this issue is high, with potential exposure of assets in the environment susceptible to exploitation, affecting confidentiality.
Recommendations
For Apache XML Graphics versions prior to 1.16, update to version 1.16.
For Confluence Data Center and Server versions 7.13.0 through 7.19.0, upgrade to a release greater than or equal to 7.19.16.
As a temporary workaround, consider restricting the use of SVG images in your environment until the issue is resolved.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Batik
Apache Xml Graphics
Astra Linux
Confluence
Jira
Linuxmint
Red Os
Suse
Ubuntu