CVE-2022-44729: Apache XML Graphics Batik: Information disclosure vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Batik vulnerability?
The vulnerability ID for this Apache Batik vulnerability is CVE-2022-44729.
What is the title of this Apache Batik vulnerability?
The title of this Apache Batik vulnerability is Re: [CVE-2022-44729] Apache Batik information disclosure vulnerability.
What is the severity of CVE-2022-44729?
The severity of CVE-2022-44729 is high with a CVSS score of 7.1.
Which version of Apache XML Graphics Batik is affected by this vulnerability?
Apache XML Graphics Batik version 1.16 is affected by this vulnerability.
How can I fix CVE-2022-44729?
To fix CVE-2022-44729, update Apache XML Graphics Batik to version 1.17.