CVE-2022-41704
Summary
| CVE | CVE-2022-41704 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-25 17:15:00 UTC |
| Updated | 2024-01-07 11:15:00 UTC |
| Description | A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Batik | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - [CVE-2022-41704] Apache Batik information disclosure vulnerability | MLIST | www.openwall.com | |
| lists.apache.org/thread/hplhx0o74jb7blj39fm4kw3otcnjd6xf | MISC | lists.apache.org | |
| [SECURITY] [DLA 3169-1] batik security update | MLIST | lists.debian.org | |
| GLSA-202401-11 | security.gentoo.org | ||
| Debian -- Security Information -- DSA-5264-1 batik | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was independently reported by 4ra1n of Chaitin Tech and pwnull
Legacy QID Mappings
- 181174 Debian Security Update for batik (DLA 3169-1)
- 181176 Debian Security Update for batik (DSA 5264-1)
- 182699 Debian Security Update for batik (CVE-2022-41704)
- 199377 Ubuntu Security Notification for Apache Batik Vulnerabilities (USN-6117-1)
- 354806 Amazon Linux Security Advisory for batik : ALAS2-2023-1966
- 354807 Amazon Linux Security Advisory for batik : ALAS-2023-1695
- 355063 Amazon Linux Security Advisory for batik : AL2012-2023-387
- 710829 Gentoo Linux Apache Batik Multiple Vulnerabilities (GLSA 202401-11)
- 730979 Atlassian Confluence Data Center and Server Multiple Vulnerabilities (CONFSERVER-93179,CONFSERVER-93178,CONFSERVER-93175)
- 731296 Atlassian Jira Software Data Center and Server Remote Code Execution (RCE) Vulnerability (JSWSERVER-25800)
- 755916 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0777-1)
- 755935 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0808-1)