CVE-2022-44729
Last modified
CVE-2022-44729 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Xml Graphics Batik | >= 1.0, <= 1.16 |
| Debian | Debian Linux | 10.0 |
References
- http://www.openwall.com/lists/oss-security/2023/08/22/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2Mailing List, Vendor Advisory
- https://xmlgraphics.apache.org/security.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/08/22/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/hco2nw1typoorz33qzs0fcdx0ws6d6j2Mailing List, Vendor Advisory
- https://xmlgraphics.apache.org/security.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-44729?
How severe is CVE-2022-44729?
How do I fix CVE-2022-44729?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-44720An issue was discovered in Weblib Ucopia before 6.0.13. OS C…9.8
- CVE-2022-44721Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-44724The Handy Tip macro in Stiltsoft Handy Macros for Confluence…5.4
- CVE-2022-44725OPC Foundation Local Discovery Server (LDS) through 1.04.403…7.8
- CVE-2022-44726The TouchDown Timesheet tracking component 4.1.4 for Jira al…5.4
- CVE-2022-44727The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.…9.1
- CVE-2022-4473The Widget Shortcode WordPress plugin through 0.3.5 does not…5.4
- CVE-2022-44730Server-Side Request Forgery (SSRF) vulnerability in Apache S…4.4
- CVE-2022-44731A vulnerability has been identified in SIMATIC WinCC OA V3.1…5.4
- CVE-2022-44732Local privilege escalation due to insecure folder permission…7.8
- CVE-2022-44733Local privilege escalation due to insecure folder permission…7.8
- CVE-2022-44734Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
Are you affected by CVE-2022-44729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
