CVE-2022-38648
published 2022-09-22CVE-2022-38648: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.95%
78.0th percentile
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | — | — |
| apache | batik | >= 0 < 1.12-4+deb11u3 | 1.12-4+deb11u3 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| apache_software_foundation | apache_xml_graphics | — | — |
| debian | batik | < batik 1.15+dfsg-1 (bookworm) | batik 1.15+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
GHSA
Apache Batik vulnerable to Server-Side Request Forgery
ghsa·2022-09-23
CVE-2022-38648 [MEDIUM] CWE-918 Apache Batik vulnerable to Server-Side Request Forgery
Apache Batik vulnerable to Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik Bridge versions 1.14 and below.
OSV
Apache Batik vulnerable to Server-Side Request Forgery
osv·2022-09-23
CVE-2022-38648 [MEDIUM] Apache Batik vulnerable to Server-Side Request Forgery
Apache Batik vulnerable to Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik Bridge versions 1.14 and below.
OSV
CVE-2022-38648: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources
osv·2022-09-22·CVSS 5.3
CVE-2022-38648 [MEDIUM] CVE-2022-38648: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
batik: Server-Side Request Forgery
vendor_redhat·2022-09-22·CVSS 5.3
CVE-2022-38648 [MEDIUM] CWE-918 batik: Server-Side Request Forgery
batik: Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Package: batik (Red Hat build of Quarkus) - Will not fix
Package: batik (Red Hat Decision Manager 7) - Out of support scope
Package: batik (Red Hat Integration Camel K 1) - Affected
Package: batik (Red Hat Integration Camel Quarkus 1) - Will not fix
Package: batik (Red Hat JBoss Data Grid 7) - Out of support scope
Package: batik (Red Hat JBoss Fuse 6) - Out of support scope
Package: batik (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: batik (Red Hat Process Automation 7) - Out of support scope
Debian
CVE-2022-38648: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...
vendor_debian·2022·CVSS 5.3
CVE-2022-38648 [MEDIUM] CVE-2022-38648: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Scope: local
bookworm: resolved (fixed in 1.15+dfsg-1)
bullseye: resolved (fixed in 1.12-4+deb11u3)
forky: resolved (fixed in 1.15+dfsg-1)
sid: resolved (fixed in 1.15+dfsg-1)
trixie: resolved (fixed in 1.15+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread/gfsktxvj7jtwyovmhhbrw0bs13wfjd7bhttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://security.gentoo.org/glsa/202401-11https://lists.apache.org/thread/gfsktxvj7jtwyovmhhbrw0bs13wfjd7bhttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2025/07/msg00006.htmlhttps://security.gentoo.org/glsa/202401-11
2022-09-22
Published