CVE-2022-44729
Last modified
CVE-2022-44729 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Xml Graphics Batik | >= 1.0, <= 1.16 |
| Debian | Debian Linux | 10.0 |
References
- http://www.openwall.com/lists/oss-security/2023/08/22/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2Mailing List, Vendor Advisory
- https://xmlgraphics.apache.org/security.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2Mailing List, Vendor Advisory
- https://xmlgraphics.apache.org/security.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-44729?
How severe is CVE-2022-44729?
How do I fix CVE-2022-44729?
Are you affected by CVE-2022-44729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
