CVE-2022-41704: Apache Batik prior to 1.16 allows RCE when loading untrusted SVG input
A flaw was found in Batik. This issue may allow a malicious user to run untrusted Java code from an SVG.
Other sources
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.xmlgraphics:batikto a version that resolves this vulnerability.Fixed in 1.16 - Upgrade
Upgrade
redhat/org.apache.xmlgraphics batikto a version that resolves this vulnerability.Fixed in 1.16 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.10-2+deb10u3Fixed in 1.12-4+deb11u2Fixed in 1.12-4+deb11u1Fixed in 1.16+dfsg-1+deb12u1Fixed in 1.17+dfsg-1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.10-2~18.04.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.12-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.14-1ubuntu0.2 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.14-2ubuntu0.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.7.ubuntu-8ubuntu2.14.04.3+ - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.8-3ubuntu1+ - Upgrade
Upgrade
Apache Batik (Apache XML Graphics)to a version that resolves this vulnerability.Fixed in 1.16 - Compensating control
If you cannot update immediately, avoid loading untrusted SVG input into Apache Batik, since the vulnerability allows execution of untrusted Java code from an SVG.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in Batik?
The vulnerability ID for this flaw in Batik is CVE-2022-41704.
What is the severity level of CVE-2022-41704?
CVE-2022-41704 has a severity level of high.
What is the affected software for CVE-2022-41704?
The affected software for CVE-2022-41704 is Batik of Apache XML Graphics prior to version 1.16.
How can I fix CVE-2022-41704?
To fix CVE-2022-41704, it is recommended to update to version 1.16 of Apache XML Graphics.
Where can I find more information about CVE-2022-41704?
You can find more information about CVE-2022-41704 at the following references: [Link 1](https://lists.apache.org/thread/hplhx0o74jb7blj39fm4kw3otcnjd6xf), [Link 2](http://www.openwall.com/lists/oss-security/2022/10/25/2), [Link 3](https://www.debian.org/security/2022/dsa-5264).