Apache XML Graphics Batik: Information disclosure vulnerability
CVE-2022-44729

7.1HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
22 August 2023

Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in version 1.16 of Apache XML Graphics Batik. This flaw can be exploited when a malicious SVG file causes the application to load external resources by default. This behavior may lead to excessive resource consumption and can result in unauthorized information disclosure. To safeguard against these risks, users are advised to upgrade to version 1.17 or a later version.

Affected Version(s)

Apache XML Graphics Batik 1.16

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nbxiglk
.