PT-2023-7021 · Apache +2 · Apache Xml Graphics Batik +2
Nbxiglk
·
Published
2023-08-22
·
Updated
2024-03-08
·
CVE-2022-44729
7.1
High
Base vector | Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache XML Graphics Batik version 1.16
Description:
The issue is related to a Server-Side Request Forgery (SSRF) vulnerability in Apache XML Graphics Batik. This vulnerability can be exploited by a malicious SVG, which could trigger the loading of external resources by default, causing resource consumption or, in some cases, information disclosure.
Recommendations:
For Apache XML Graphics Batik version 1.16, upgrade to version 1.17 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable component to minimize the risk of exploitation. Avoid using the vulnerable version of Apache XML Graphics Batik until the issue is resolved.
Exploit
Fix
SSRF
Weakness Enumeration
Related Identifiers
Affected Products
References · 70
- 🔥 https://github.com/cckuailong/CVE-2022-40146_Exploit_Jar⭐ 31 🔗 6 · Exploit
- https://osv.dev/vulnerability/SUSE-SU-2024:0808-1 · Vendor Advisory
- https://osv.dev/vulnerability/SUSE-SU-2024:0777-1 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2022-44729 · Vendor Advisory
- https://osv.dev/vulnerability/UBUNTU-CVE-2022-44729 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38398 · Security Note
- https://bdu.fstec.ru/vul/2022-06660 · Security Note
- https://osv.dev/vulnerability/DLA-3619-1 · Vendor Advisory
- https://ubuntu.com/security/CVE-2022-44729 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38648 · Security Note
- https://osv.dev/vulnerability/GHSA-gq5f-xv48-2365 · Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2022-44729 · Vendor Advisory
- https://bdu.fstec.ru/vul/2023-08076 · Security Note
- https://cve.org/CVERecord?id=CVE-2022-44729 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11987 · Security Note