PT-2023-7054 · Apache+2 · Apache Xml Graphics Batik+2

Julien Lacour

·

Published

2023-08-22

·

Updated

2024-03-08

·

CVE-2022-44730

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache XML Graphics Batik version 1.16
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability in the Apache XML Graphics Batik library, which is used for working with SVG images. This vulnerability is caused by insufficient checking of incoming requests. Exploitation of this vulnerability can allow an attacker to perform an SSRF attack, which can probe user profile/data and send it directly as a parameter to a URL. A malicious SVG can be used to exploit this vulnerability.
Recommendations For Apache XML Graphics Batik version 1.16, consider disabling the processing of SVG images until a patch is available. Restrict access to the vulnerable library to minimize the risk of exploitation. Avoid using the library to process untrusted SVG images until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BDU:2023-08076
CVE-2022-44730
DLA-3619-1
GHSA-2474-2566-3QXP
OESA-2023-1651
OPENSUSE-SU-2024:13743-1
OPENSUSE-SU-2024_0808-1
SUSE-SU-2024:0777-1
SUSE-SU-2024:0808-1

Affected Products

Apache Xml Graphics Batik
Astra Linux
Suse