CVE-2022-38398: Server-Side Request Forgery Information Disclosure Vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38398?
CVE-2022-38398 is a Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics.
How does CVE-2022-38398 affect Apache XML Graphics Batik?
CVE-2022-38398 allows an attacker to load a URL through the jar protocol in Apache XML Graphics Batik.
What is the severity of CVE-2022-38398?
CVE-2022-38398 has a severity rating of medium with a score of 5.3.
How can I fix CVE-2022-38398?
To fix CVE-2022-38398, update to version 1.15 of Batik for redhat or apply the appropriate remedy for your Ubuntu or Debian distribution.
Where can I find more information about CVE-2022-38398?
You can find more information about CVE-2022-38398 at the following references: [link](https://lists.apache.org/thread/712c9xwtmyghyokzrm2ml6sps4xlmbsx), [link](https://launchpad.net/bugs/cve/CVE-2022-38398), [link](https://www.cve.org/CVERecord?id=CVE-2022-38398), [link](https://nvd.nist.gov/vuln/detail/CVE-2022-38398), [link](http://svn.apache.org/viewvc?view=revision&revision=1903462), [link](https://issues.apache.org/jira/browse/BATIK-1331).