CVE-2022-40146
published 2022-09-22CVE-2022-40146: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
5.79%
92.3th percentile
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | — | — |
| apache | batik | >= 0 < 1.12-4+deb11u3 | 1.12-4+deb11u3 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.15+dfsg-1 | 1.15+dfsg-1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| apache_software_foundation | apache_xml_graphics | — | — |
| atlassian | jira_software | — | — |
| debian | batik | < batik 1.15+dfsg-1 (bookworm) | batik 1.15+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →SSRF vector uses the 'jar:' URL scheme to access arbitrary files; monitor or block requests containing 'jar:' URLs in SVG/XML content processed by Batik ↗
- →The vulnerable component is the batik-bridge artifact; flag presence of org.apache.xmlgraphics:batik-bridge at version 1.14 in dependency scans ↗
- ·Only Apache XML Graphics Batik version 1.14 is confirmed affected; versions 1.15+ (e.g., 1.15+dfsg-1 on Debian) are fixed ↗
- ·Exploitation is possible remotely over HTTP; no authentication barrier is implied by the advisory ↗
- ·Red Hat packages for batik in Red Hat Integration Camel K 1 are listed as Affected with no fix committed; deployments using these packages remain exposed ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
GHSA
Apache Batik vulnerable to Server-Side Request Forgery
ghsa·2022-09-23
CVE-2022-40146 [HIGH] CWE-918 Apache Batik vulnerable to Server-Side Request Forgery
Apache Batik vulnerable to Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
OSV
Apache Batik vulnerable to Server-Side Request Forgery
osv·2022-09-23
CVE-2022-40146 [HIGH] Apache Batik vulnerable to Server-Side Request Forgery
Apache Batik vulnerable to Server-Side Request Forgery
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
OSV
CVE-2022-40146: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url
osv·2022-09-22·CVSS 7.5
CVE-2022-40146 [HIGH] CVE-2022-40146: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
Atlassian
CVE-2022-40146: SSRF (Server-Side Request Forgery) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Serve
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-40146 [HIGH] CVE-2022-40146: SSRF (Server-Side Request Forgery) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Serve
CVE-2022-40146: SSRF (Server-Side Request Forgery) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Serve
SSRF (Server-Side Request Forgery) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Server
CVE: CVE-2022-40146
Affected products: Jira Software
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Batik) — CVE-2022-40146
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-40146 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Batik) — CVE-2022-40146
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure (Apache Batik) vulnerability
CVE: CVE-2022-40146
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Utilities (Apache Batik) — CVE-2022-40146
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-40146 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Utilities (Apache Batik) — CVE-2022-40146
Oracle Oracle Communications Applications Risk Matrix: Utilities (Apache Batik) vulnerability
CVE: CVE-2022-40146
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
batik: Server-Side Request Forgery (SSRF) vulnerability
vendor_redhat·2022-09-22·CVSS 7.5
CVE-2022-40146 [HIGH] CWE-918 batik: Server-Side Request Forgery (SSRF) vulnerability
batik: Server-Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
Package: batik (Red Hat build of Quarkus) - Will not fix
Package: batik (Red Hat Decision Manager 7) - Out of support scope
Package: batik (Red Hat Integration Camel K 1) - Affected
Package: batik (Red Hat Integration Camel Quarkus 1) - Will not fix
Package: batik (Red Hat JBoss Data Grid 7) - Out of support scope
Package: batik (Red Hat JBoss Fuse 6) - Out of support scope
Package: batik (Red Hat JBoss Fuse Service Works 6) - Out of support scope
Package: batik (Red Hat Process Automation 7) - Out of support scope
Debian
CVE-2022-40146: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...
vendor_debian·2022·CVSS 7.5
CVE-2022-40146 [HIGH] CVE-2022-40146: batik - Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics...
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
Scope: local
bookworm: resolved (fixed in 1.15+dfsg-1)
bullseye: resolved (fixed in 1.12-4+deb11u3)
forky: resolved (fixed in 1.15+dfsg-1)
sid: resolved (fixed in 1.15+dfsg-1)
trixie: resolved (fixed in 1.15+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread/hxtddqjty2sbs12y97c8g7xfh17jzxsxhttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://security.gentoo.org/glsa/202401-11https://lists.apache.org/thread/hxtddqjty2sbs12y97c8g7xfh17jzxsxhttps://lists.debian.org/debian-lts-announce/2023/10/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2025/07/msg00006.htmlhttps://security.gentoo.org/glsa/202401-11
2022-09-22
Published