cbcvebase.
CVE-2022-40146
published 2022-09-22

CVE-2022-40146: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache…

PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
5.79%
92.3th percentile
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachebatik
apachebatik>= 0 < 1.12-4+deb11u31.12-4+deb11u3
apachebatik>= 0 < 1.15+dfsg-11.15+dfsg-1
apachebatik>= 0 < 1.15+dfsg-11.15+dfsg-1
apachebatik>= 0 < 1.15+dfsg-11.15+dfsg-1
apachebatik>= 0 < 1.10-2~18.04.11.10-2~18.04.1
apachebatik>= 0 < 1.12-1ubuntu0.11.12-1ubuntu0.1
apachebatik>= 0 < 1.14-1ubuntu0.21.14-1ubuntu0.2
apachebatik>= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm11.7.ubuntu-8ubuntu2.14.04.3+esm1
apachebatik>= 0 < 1.8-3ubuntu1+esm11.8-3ubuntu1+esm1
apache_software_foundationapache_xml_graphics
atlassianjira_software
debianbatik< batik 1.15+dfsg-1 (bookworm)batik 1.15+dfsg-1 (bookworm)
debiandebian_linux

Detection & IOCsextracted from sources · hover to see the quote

  • SSRF vector uses the 'jar:' URL scheme to access arbitrary files; monitor or block requests containing 'jar:' URLs in SVG/XML content processed by Batik
  • The vulnerable component is the batik-bridge artifact; flag presence of org.apache.xmlgraphics:batik-bridge at version 1.14 in dependency scans
  • ·Only Apache XML Graphics Batik version 1.14 is confirmed affected; versions 1.15+ (e.g., 1.15+dfsg-1 on Debian) are fixed
  • ·Exploitation is possible remotely over HTTP; no authentication barrier is implied by the advisory
  • ·Red Hat packages for batik in Red Hat Integration Camel K 1 are listed as Affected with no fix committed; deployments using these packages remain exposed

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.