CVE-2019-17566
published 2020-11-12CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted…
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
10.74%
95.3th percentile
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | < 1.13 | 1.13 |
| apache | batik | >= 0 < 1.12-1.1 | 1.12-1.1 |
| apache | batik | >= 0 < 1.12-1.1 | 1.12-1.1 |
| apache | batik | >= 0 < 1.12-1.1 | 1.12-1.1 |
| apache | batik | >= 0 < 1.12-1.1 | 1.12-1.1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| debian | batik | < batik 1.12-1.1 (bookworm) | batik 1.12-1.1 (bookworm) |
| oracle | api_gateway | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_metasolv_solution | 6.3.0 – 6.3.1 | — |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | enterprise_repository | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.1.0 | — |
| oracle | fusion_middleware_mapviewer | — | — |
| oracle | hospitality_opera_5 | — | — |
| oracle | hospitality_opera_5 | — | — |
| oracle | hyperion_financial_reporting | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
OSV
Server-side request forgery (SSRF) in Apache Batik
osv·2022-02-09
CVE-2019-17566 [HIGH] Server-side request forgery (SSRF) in Apache Batik
Server-side request forgery (SSRF) in Apache Batik
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
GHSA
Server-side request forgery (SSRF) in Apache Batik
ghsa·2022-02-09
CVE-2019-17566 [HIGH] CWE-20 Server-side request forgery (SSRF) in Apache Batik
Server-side request forgery (SSRF) in Apache Batik
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
OSV
CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes
osv·2020-11-12·CVSS 7.5
CVE-2019-17566 [HIGH] CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Web Answers (Apache Batik) — CVE-2019-17566
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2019-17566 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Analytics Web Answers (Apache Batik) — CVE-2019-17566
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Web Answers (Apache Batik) vulnerability
CVE: CVE-2019-17566
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: CN OCOMC (Apache Batik) — CVE-2019-17566
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2019-17566 [HIGH] Oracle Oracle Communications Applications Risk Matrix: CN OCOMC (Apache Batik) — CVE-2019-17566
Oracle Oracle Communications Applications Risk Matrix: CN OCOMC (Apache Batik) vulnerability
CVE: CVE-2019-17566
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Rate Management (Apache Batik) — CVE-2019-17566
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2019-17566 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Rate Management (Apache Batik) — CVE-2019-17566
Oracle Oracle Financial Services Applications Risk Matrix: Rate Management (Apache Batik) vulnerability
CVE: CVE-2019-17566
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Batik) — CVE-2019-17566
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2019-17566 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Batik) — CVE-2019-17566
Oracle Oracle Communications Applications Risk Matrix: Print Preview (Apache Batik) vulnerability
CVE: CVE-2019-17566
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
batik: SSRF via "xlink:href"
vendor_redhat·2020-06-15·CVSS 7.5
CVE-2019-17566 [HIGH] CWE-352 batik: SSRF via "xlink:href"
batik: SSRF via "xlink:href"
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
A flaw was found in the Apache Batik library, where it is vulnerable to a Server-Side Request Forgery attack (SSRF) via "xlink:href" attributes. This flaw allows an attacker to cause the underlying server to make arbitrary GET requests. The highest threat from this vulnerability is to system integrity.
Package: batik (Red Hat BPM Suite 6) - Out of support scope
Package: batik (Red Hat Enterprise Linux 6) - Out of support scope
Package: batik (Red Hat Enterprise Linux 7) - Will not fix
P
Debian
CVE-2019-17566: batik - Apache Batik is vulnerable to server-side request forgery, caused by improper in...
vendor_debian·2019·CVSS 7.5
CVE-2019-17566 [HIGH] CVE-2019-17566: batik - Apache Batik is vulnerable to server-side request forgery, caused by improper in...
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Scope: local
bookworm: resolved (fixed in 1.12-1.1)
bullseye: resolved (fixed in 1.12-1.1)
forky: resolved (fixed in 1.12-1.1)
sid: resolved (fixed in 1.12-1.1)
trixie: resolved (fixed in 1.12-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17566 batik: SSRF via "xlink:href"
bugzilla·2020-06-18·CVSS 7.5
CVE-2019-17566 [HIGH] CVE-2019-17566 batik: SSRF via "xlink:href"
CVE-2019-17566 batik: SSRF via "xlink:href"
The Apache Batik library is vulnerable to SSRF via "xlink:href" attributes that allow an attacker to cause the underlying server to make arbitrary GET requests.
References:
https://www.openwall.com/lists/oss-security/2020/06/15/2
Discussion:
Created batik tracking bugs for this issue:
Affects: fedora-all [bug 1848619]
---
Upstream Issue:
https://issues.apache.org/jira/projects/BATIK/issues/BATIK-1276
Fixing Commit:
bc6078ca949039e2076cd08b4cb169c84c1179b1 (https://github.com/apache/xmlgraphics-batik/commit/bc6078ca949039e2076cd08b4cb169c84c1179b1)
Affects GAVs:
org.apache.xmlgraphics:batik-transcoder
org.apache.xmlgraphics:batik-svgrasterizer
org.apache.xmlgraphics:batik-all
---
This issue has been addressed in the following products:
Bugzilla
CVE-2019-17566 batik: SSRF via "xlink:href" [fedora-all]
bugzilla·2020-06-18·CVSS 7.5
CVE-2019-17566 [HIGH] CVE-2019-17566 batik: SSRF via "xlink:href" [fedora-all]
CVE-2019-17566 batik: SSRF via "xlink:href" [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While onl
https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apache.org%3Ehttps://security.gentoo.org/glsa/202401-11https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://xmlgraphics.apache.org/security.htmlhttps://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apache.org%3Ehttps://security.gentoo.org/glsa/202401-11https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://xmlgraphics.apache.org/security.html
2020-11-12
Published