CVE-2022-38648

Severity
5.3MEDIUM
EPSS
0.2%
top 54.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22
Latest updateMay 30

Description

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages6 packages

NVDapache/batik1.14
Debianbatik< 1.12-4+deb11u3+3

Also affects: Debian Linux 10.0

🔴Vulnerability Details

5
OSV
batik vulnerabilities2023-05-30
GHSA
Apache Batik vulnerable to Server-Side Request Forgery2022-09-23
OSV
Apache Batik vulnerable to Server-Side Request Forgery2022-09-23
CVEList
PDFTranscoder does not block external resources2022-09-22
OSV
CVE-2022-38648: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources2022-09-22

📋Vendor Advisories

3
Ubuntu
Apache Batik vulnerabilities2023-05-30
Red Hat
batik: Server-Side Request Forgery2022-09-22
Debian
CVE-2022-38648: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...2022
CVE-2022-38648 (MEDIUM CVSS 5.3) | Server-Side Request Forgery (SSRF) | cvebase.io