CVE-2022-38398
published 2022-09-22CVE-2022-38398: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.02%
78.7th percentile
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | — | — |
| apache | batik | >= 0 < 1.12-4+deb11u3 | 1.12-4+deb11u3 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| apache_software_foundation | apache_xml_graphics | — | — |
| debian | batik | < batik 1.15+dfsg-1 (bookworm) | batik 1.15+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
GHSA
Apache Batik Server-Side Request Forgery
ghsa·2022-09-23
CVE-2022-38398 [MEDIUM] CWE-918 Apache Batik Server-Side Request Forgery
Apache Batik Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
OSV
Apache Batik Server-Side Request Forgery
osv·2022-09-23
CVE-2022-38398 [MEDIUM] Apache Batik Server-Side Request Forgery
Apache Batik Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
OSV
CVE-2022-38398: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol
osv·2022-09-22·CVSS 5.3
CVE-2022-38398 [MEDIUM] CVE-2022-38398: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
batik: Server-Side Request Forgery
vendor_redhat·2022-09-22·CVSS 5.3
CVE-2022-38398 [MEDIUM] CWE-918 batik: Server-Side Request Forgery
batik: Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Package: batik (Red Hat build of Quarkus) - Will not fix
Package: batik (Red Hat Decision Manager 7) - Out of support scope
Package: batik (Red Hat Integration Camel K 1) - Affected
Package: batik (Red Hat Integration Camel Quarkus 1) - Will not fix
Package: batik (Red Hat JBoss Data Grid 7) - Out of support scope
Package: batik (Red Hat JBoss Fuse 6) - Out of support scope
Package: batik (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: batik (Red Hat Process Automation 7) - Out of support scope
Debian
CVE-2022-38398: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...
vendor_debian·2022·CVSS 5.3
CVE-2022-38398 [MEDIUM] CVE-2022-38398: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Scope: local
bookworm: resolved (fixed in 1.15+dfsg-1)
bullseye: resolved (fixed in 1.12-4+deb11u3)
forky: resolved (fixed in 1.15+dfsg-1)
sid: resolved (fixed in 1.15+dfsg-1)
trixie: resolved (fixed in 1.15+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread/712c9xwtmyghyokzrm2ml6sps4xlmbsxhttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://security.gentoo.org/glsa/202401-11https://lists.apache.org/thread/712c9xwtmyghyokzrm2ml6sps4xlmbsxhttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2025/07/msg00006.htmlhttps://security.gentoo.org/glsa/202401-11
2022-09-22
Published