CVE-2022-42890: Apache Batik prior to 1.16 allows RCE via scripting
A flaw was found in Batik of Apache XML Graphics. This issue may allow a malicious user to run Java code from untrusted SVG via JavaScript.
Other sources
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.xmlgraphics:batikto a version that resolves this vulnerability.Fixed in 1.16 - Upgrade
Upgrade
redhat/org.apache.xmlgraphics batikto a version that resolves this vulnerability.Fixed in 1.16 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.10-2+deb10u3Fixed in 1.12-4+deb11u2Fixed in 1.12-4+deb11u1Fixed in 1.16+dfsg-1+deb12u1Fixed in 1.17+dfsg-1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.10-2~18.04.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.12-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.14-1ubuntu0.2 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.14-2ubuntu0.1 - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.7.ubuntu-8ubuntu2.14.04.3+ - Upgrade
Upgrade
ubuntu/batikto a version that resolves this vulnerability.Fixed in 1.8-3ubuntu1+ - Upgrade
Upgrade
Apache XML Graphics Batikto a version that resolves this vulnerability.Fixed in 1.16
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2022-42890.
What is the severity of CVE-2022-42890?
CVE-2022-42890 has a severity level of high.
What is the affected software version for CVE-2022-42890?
The affected software version for CVE-2022-42890 is Apache XML Graphics prior to 1.16.
How can I fix the vulnerability CVE-2022-42890?
To fix CVE-2022-42890, users are recommended to upgrade to version 1.16 of Apache XML Graphics.
Where can I find more information about CVE-2022-42890?
More information about CVE-2022-42890 can be found at the following references: [link1](https://lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwly), [link2](http://www.openwall.com/lists/oss-security/2022/10/25/3), [link3](https://www.debian.org/security/2022/dsa-5264).