CVE-2022-42890
published 2022-10-25CVE-2022-42890: A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.32%
81.7th percentile
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | batik | >= 0 < 1.12-4+deb11u1 | 1.12-4+deb11u1 |
| apache | batik | >= 0 < 1.16+dfsg-1 | 1.16+dfsg-1 |
| apache | batik | >= 0 < 1.16+dfsg-1 | 1.16+dfsg-1 |
| apache | batik | >= 0 < 1.16+dfsg-1 | 1.16+dfsg-1 |
| apache | batik | >= 0 < 1.10-2~18.04.1 | 1.10-2~18.04.1 |
| apache | batik | >= 0 < 1.12-1ubuntu0.1 | 1.12-1ubuntu0.1 |
| apache | batik | >= 0 < 1.14-1ubuntu0.2 | 1.14-1ubuntu0.2 |
| apache | batik | >= 0 < 1.7.ubuntu-8ubuntu2.14.04.3+esm1 | 1.7.ubuntu-8ubuntu2.14.04.3+esm1 |
| apache | batik | >= 0 < 1.8-3ubuntu1+esm1 | 1.8-3ubuntu1+esm1 |
| apache | batik | >= 1.0 < 1.16 | 1.16 |
| apache_software_foundation | apache_xml_graphics | Batik – 1.15 | — |
| atlassian | jira_software | — | — |
| debian | batik | < batik 1.16+dfsg-1 (bookworm) | batik 1.16+dfsg-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
batik vulnerabilities
osv·2023-05-30·CVSS 7.5
CVE-2019-17566 [HIGH] batik vulnerabilities
batik vulnerabilities
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
OSV
Untrusted code execution in Apache XML Graphics Batik
osv·2022-10-25
CVE-2022-42890 [HIGH] Untrusted code execution in Apache XML Graphics Batik
Untrusted code execution in Apache XML Graphics Batik
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
GHSA
Untrusted code execution in Apache XML Graphics Batik
ghsa·2022-10-25
CVE-2022-42890 [HIGH] CWE-918 Untrusted code execution in Apache XML Graphics Batik
Untrusted code execution in Apache XML Graphics Batik
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
OSV
CVE-2022-42890: A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript
osv·2022-10-25·CVSS 7.5
CVE-2022-42890 [HIGH] CVE-2022-42890: A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
Oracle
Oracle Oracle Communications Risk Matrix: Security (Apache Batik) — CVE-2022-42890
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2022-42890 [HIGH] Oracle Oracle Communications Risk Matrix: Security (Apache Batik) — CVE-2022-42890
Oracle Oracle Communications Risk Matrix: Security (Apache Batik) vulnerability
CVE: CVE-2022-42890
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Web General (Apache Batik) — CVE-2022-42890
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2022-42890 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Web General (Apache Batik) — CVE-2022-42890
Oracle Oracle Analytics Risk Matrix: Analytics Web General (Apache Batik) vulnerability
CVE: CVE-2022-42890
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Atlassian
CVE-2022-42890: RCE (Remote Code Execution) org.apache.xmlgraphics:batik-script Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-03-19·CVSS 7.5
CVE-2022-42890 [HIGH] CVE-2022-42890: RCE (Remote Code Execution) org.apache.xmlgraphics:batik-script Dependency in Jira Software Data Center and Server
CVE-2022-42890: RCE (Remote Code Execution) org.apache.xmlgraphics:batik-script Dependency in Jira Software Data Center and Server
RCE (Remote Code Execution) org.apache.xmlgraphics:batik-script Dependency in Jira Software Data Center and Server
CVE: CVE-2022-42890
Affected products: Jira Software
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Batik) — CVE-2022-42890
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-42890 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Batik) — CVE-2022-42890
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Batik) vulnerability
CVE: CVE-2022-42890
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Ubuntu
Apache Batik vulnerabilities
vendor_ubuntu·2023-05-30·CVSS 7.5
CVE-2022-40146 [HIGH] Apache Batik vulnerabilities
Title: Apache Batik vulnerabilities
Summary: Several security issues were fixed in Apache Batik.
It was discovered that Apache Batik incorrectly handled certain inputs. An
attacker could possibly use this to perform a cross site request forgery
attack. (CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648)
It was discovered that Apache Batik incorrectly handled Jar URLs in some
situations. A remote attacker could use this issue to access files on the
server. (CVE-2022-40146)
It was discovered that Apache Batik allowed running untrusted Java code from
an SVG. An attacker could use this issue to cause a denial of service,
or possibly execute arbitrary code. (CVE-2022-41704, CVE-2022-42890)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: UI General (Apache Batik) — CVE-2022-42890
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-42890 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: UI General (Apache Batik) — CVE-2022-42890
Oracle Oracle Financial Services Applications Risk Matrix: UI General (Apache Batik) vulnerability
CVE: CVE-2022-42890
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
batik: Untrusted code execution in Apache XML Graphics Batik
vendor_redhat·2022-10-25·CVSS 7.5
CVE-2022-42890 [HIGH] CWE-918 batik: Untrusted code execution in Apache XML Graphics Batik
batik: Untrusted code execution in Apache XML Graphics Batik
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
A flaw was found in Batik of Apache XML Graphics. This issue may allow a malicious user to run Java code from untrusted SVG via JavaScript.
Package: batik (Red Hat Decision Manager 7) - Out of support scope
Package: batik (Red Hat Integration Camel K 1) - Will not fix
Package: batik (Red Hat Integration Camel Quarkus 2) - Will not fix
Package: batik (Red Hat JBoss Data Grid 7) - Out of support scope
Package: batik (Red Hat Process Automation 7) - Out of support scope
Debian
CVE-2022-42890: batik - A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java c...
vendor_debian·2022·CVSS 7.5
CVE-2022-42890 [HIGH] CVE-2022-42890: batik - A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java c...
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
Scope: local
bookworm: resolved (fixed in 1.16+dfsg-1)
bullseye: resolved (fixed in 1.12-4+deb11u1)
forky: resolved (fixed in 1.16+dfsg-1)
sid: resolved (fixed in 1.16+dfsg-1)
trixie: resolved (fixed in 1.16+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/10/25/3https://lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwlyhttps://lists.debian.org/debian-lts-announce/2022/10/msg00038.htmlhttps://security.gentoo.org/glsa/202401-11https://www.debian.org/security/2022/dsa-5264http://www.openwall.com/lists/oss-security/2022/10/25/3https://lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwlyhttps://lists.debian.org/debian-lts-announce/2022/10/msg00038.htmlhttps://security.gentoo.org/glsa/202401-11https://www.debian.org/security/2022/dsa-5264
2022-10-25
Published