CVE-2019-17566: CSRF
A flaw was found in the Apache Batik library, where it is vulnerable to a Server-Side Request Forgery attack (SSRF) via "xlink:href" attributes. This flaw allows an attacker to cause the underlying server to make arbitrary GET requests. The highest threat from this vulnerability is to system integrity.
Other sources
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
— Ubuntu
The Apache Batik library is vulnerable to SSRF via "xlink:href" attributes that allow an attacker to cause the underlying server to make arbitrary GET requests.
References: https://www.openwall.com/lists/oss-security/2020/06/15/2
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.xmlgraphics:batikto a version that resolves this vulnerability.Fixed in 1.13 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.10-2+deb10u1Fixed in 1.10-2+deb10u3Fixed in 1.12-4+deb11u2Fixed in 1.12-4+deb11u1Fixed in 1.16+dfsg-1+deb12u1Fixed in 1.17+dfsg-1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.10-2~18.04.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.12-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.7.ubuntu-8ubuntu2.14.04.3+ - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.8-3ubuntu1+ - Upgrade
Upgrade
redhat/batikto a version that resolves this vulnerability.Fixed in 1.13 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.10-2+deb10u1 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.10-2+deb10u3 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.12-4+deb11u2 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.12-4+deb11u1 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.16+dfsg-1+deb12u1 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.17+dfsg-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-17566?
CVE-2019-17566 is a vulnerability in the Apache Batik library that allows for server-side request forgery (SSRF) attacks.
How does CVE-2019-17566 affect systems?
CVE-2019-17566 can lead to system integrity compromise by allowing attackers to make arbitrary GET requests on the underlying server.
What is the severity of CVE-2019-17566?
CVE-2019-17566 has a high severity rating, with a severity value of 7.
Which software versions are affected by CVE-2019-17566?
Versions 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.7.ubuntu-8ubuntu2.14.04.3+, and 1.8-3ubuntu1+ of the Batik library on Ubuntu are affected by CVE-2019-17566.
How can CVE-2019-17566 be fixed?
To fix CVE-2019-17566, update the Batik library to version 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.7.ubuntu-8ubuntu2.14.04.3+, or 1.8-3ubuntu1+ depending on the Ubuntu version.