Apache XML Graphics Batik: Information disclosure vulnerability
CVE-2022-44729
7.1HIGH
Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in version 1.16 of Apache XML Graphics Batik. This flaw can be exploited when a malicious SVG file causes the application to load external resources by default. This behavior may lead to excessive resource consumption and can result in unauthorized information disclosure. To safeguard against these risks, users are advised to upgrade to version 1.17 or a later version.
Affected Version(s)
Apache XML Graphics Batik 1.16
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
nbxiglk