CVE-2022-41704
published 2022-10-25CVE-2022-41704: A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.14%
80.0th percentile
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | >= 0 < 1.12-4+deb11u1 | 1.12-4+deb11u1 |
| apache | batik | >= 0 < 1.16+dfsg-1 | 1.16+dfsg-1 |
| apache | batik | >= 0 < 1.16+dfsg-1 | 1.16+dfsg-1 |
| apache | batik | >= 0 < 1.16+dfsg-1 | 1.16+dfsg-1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| apache | batik | >= 1.0 < 1.16 | 1.16 |
| apache_software_foundation | apache_xml_graphics | Batik – 1.15 | — |
| atlassian | jira_software | — | — |
| debian | batik | < batik 1.16+dfsg-1 (bookworm) | batik 1.16+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
OSV
CVE-2022-41704: A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG
osv·2022-10-25·CVSS 7.5
CVE-2022-41704 [HIGH] CVE-2022-41704: A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
OSV
Apache XML Graphics Batik vulnerable to code execution via SVG.
osv·2022-10-25
CVE-2022-41704 [HIGH] Apache XML Graphics Batik vulnerable to code execution via SVG.
Apache XML Graphics Batik vulnerable to code execution via SVG.
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
GHSA
Apache XML Graphics Batik vulnerable to code execution via SVG.
ghsa·2022-10-25
CVE-2022-41704 [HIGH] CWE-918 Apache XML Graphics Batik vulnerable to code execution via SVG.
Apache XML Graphics Batik vulnerable to code execution via SVG.
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
Atlassian
CVE-2022-41704: RCE (Remote Code Execution) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-41704 [HIGH] CVE-2022-41704: RCE (Remote Code Execution) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Server
CVE-2022-41704: RCE (Remote Code Execution) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Server
RCE (Remote Code Execution) org.apache.xmlgraphics:batik-bridge Dependency in Jira Software Data Center and Server
CVE: CVE-2022-41704
Affected products: Jira Software
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
batik: Apache XML Graphics Batik vulnerable to code execution via SVG
vendor_redhat·2022-10-25·CVSS 7.5
CVE-2022-41704 [HIGH] CWE-918 batik: Apache XML Graphics Batik vulnerable to code execution via SVG
batik: Apache XML Graphics Batik vulnerable to code execution via SVG
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
A flaw was found in Batik. This issue may allow a malicious user to run untrusted Java code from an SVG.
Package: batik (Red Hat Decision Manager 7) - Out of support scope
Package: batik (Red Hat Integration Camel K 1) - Will not fix
Package: batik (Red Hat Integration Camel Quarkus 2) - Will not fix
Package: batik (Red Hat JBoss Data Grid 7) - Out of support scope
Package: batik (Red Hat Process Automation 7) - Out of support scope
Debian
CVE-2022-41704: batik - A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrus...
vendor_debian·2022·CVSS 7.5
CVE-2022-41704 [HIGH] CVE-2022-41704: batik - A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrus...
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
Scope: local
bookworm: resolved (fixed in 1.16+dfsg-1)
bullseye: resolved (fixed in 1.12-4+deb11u1)
forky: resolved (fixed in 1.16+dfsg-1)
sid: resolved (fixed in 1.16+dfsg-1)
trixie: resolved (fixed in 1.16+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/10/25/2https://lists.apache.org/thread/hplhx0o74jb7blj39fm4kw3otcnjd6xfhttps://lists.debian.org/debian-lts-announce/2022/10/msg00038.htmlhttps://security.gentoo.org/glsa/202401-11https://www.debian.org/security/2022/dsa-5264http://www.openwall.com/lists/oss-security/2022/10/25/2https://lists.apache.org/thread/hplhx0o74jb7blj39fm4kw3otcnjd6xfhttps://lists.debian.org/debian-lts-announce/2022/10/msg00038.htmlhttps://security.gentoo.org/glsa/202401-11https://www.debian.org/security/2022/dsa-5264
2022-10-25
Published