CVE-2022-44730: Apache XML Graphics Batik: Information disclosure vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.xmlgraphics:batik-scriptto a version that resolves this vulnerability.Fixed in 1.17 - Upgrade
Upgrade
redhat/batikto a version that resolves this vulnerability.Fixed in 1.17
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44730?
The severity of CVE-2022-44730 is medium.
What is the affected software for CVE-2022-44730?
The affected software for CVE-2022-44730 is Apache XML Graphics Batik version 1.16.
How can I fix CVE-2022-44730?
To fix CVE-2022-44730, upgrade to Apache XML Graphics Batik version 1.17.
What is the CWE ID for CVE-2022-44730?
The CWE ID for CVE-2022-44730 is 918.
Where can I find more information about CVE-2022-44730?
You can find more information about CVE-2022-44730 on the NIST National Vulnerability Database (NVD) website and the Apache XML Graphics Batik security page.