CVE-2022-38398: Server-Side Request Forgery Information Disclosure Vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-38398?
CVE-2022-38398 is a Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics.
How does CVE-2022-38398 affect Apache XML Graphics Batik?
CVE-2022-38398 allows an attacker to load a URL through the jar protocol in Apache XML Graphics Batik.
What is the severity of CVE-2022-38398?
CVE-2022-38398 has a severity rating of medium with a score of 5.3.
How can I fix CVE-2022-38398?
To fix CVE-2022-38398, update to version 1.15 of Batik for redhat or apply the appropriate remedy for your Ubuntu or Debian distribution.
Where can I find more information about CVE-2022-38398?
You can find more information about CVE-2022-38398 at the following references: [link](https://lists.apache.org/thread/712c9xwtmyghyokzrm2ml6sps4xlmbsx), [link](https://launchpad.net/bugs/cve/CVE-2022-38398), [link](https://www.cve.org/CVERecord?id=CVE-2022-38398), [link](https://nvd.nist.gov/vuln/detail/CVE-2022-38398), [link](http://svn.apache.org/viewvc?view=revision&revision=1903462), [link](https://issues.apache.org/jira/browse/BATIK-1331).