CVE-2022-40146
Summary
| CVE | CVE-2022-40146 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-22 15:15:00 UTC |
| Updated | 2024-01-07 11:15:00 UTC |
| Description | Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183499 Debian Security Update for batik (CVE-2022-40146)
- 199377 Ubuntu Security Notification for Apache Batik Vulnerabilities (USN-6117-1)
- 354806 Amazon Linux Security Advisory for batik : ALAS2-2023-1966
- 354807 Amazon Linux Security Advisory for batik : ALAS-2023-1695
- 355063 Amazon Linux Security Advisory for batik : AL2012-2023-387
- 6000250 Debian Security Update for batik (DLA 3619-1)
- 710829 Gentoo Linux Apache Batik Multiple Vulnerabilities (GLSA 202401-11)
- 730979 Atlassian Confluence Data Center and Server Multiple Vulnerabilities (CONFSERVER-93179,CONFSERVER-93178,CONFSERVER-93175)
- 731299 Atlassian Jira Software Data Center and Server Server-Side Request Forgery (SSRF) Vulnerability (JSWSERVER-25799)
- 755916 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0777-1)