CVE-2022-38648: PDFTranscoder does not block external resources
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38648?
CVE-2022-38648 is a Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics that allows an attacker to fetch external resources.
Which software is affected by CVE-2022-38648?
CVE-2022-38648 affects Apache XML Graphics Batik versions 1.14 and prior.
What is the severity of CVE-2022-38648?
The severity of CVE-2022-38648 is medium, with a CVSS score of 5.3.
How do I fix CVE-2022-38648?
To fix CVE-2022-38648, update to Apache XML Graphics Batik version 1.15 or later.
Where can I find more information about CVE-2022-38648?
You can find more information about CVE-2022-38648 at the following references: [Reference 1](https://lists.apache.org/thread/gfsktxvj7jtwyovmhhbrw0bs13wfjd7b), [Reference 2](https://launchpad.net/bugs/cve/CVE-2022-38648), [Reference 3](https://www.cve.org/CVERecord?id=CVE-2022-38648), [Reference 4](https://nvd.nist.gov/vuln/detail/CVE-2022-38648), [Reference 5](http://svn.apache.org/viewvc?view=revision&revision=1903625), and [Reference 6](https://issues.apache.org/jira/browse/BATIK-1333).