CVE-2022-42890

Published on: Not Yet Published

Last Modified on: 12/08/2022 03:42:00 AM UTC

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Certain versions of Batik from Apache contain the following vulnerability:

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.

  • CVE-2022-42890 has been assigned by URL Logo secu[email protected] to track the vulnerability - currently rated as HIGH severity.
  • Affected Vendor/Software: URL Logo Apache Software Foundation - Apache XML Graphics version <= 1.15

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH NONE NONE

CVE References

Description Tags Link
No Description Provided lists.apache.org
text/html
URL Logo MISC lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwly
[SECURITY] [DLA 3169-1] batik security update lists.debian.org
text/html
URL Logo MLIST [debian-lts-announce] 20221029 [SECURITY] [DLA 3169-1] batik security update
oss-security - [CVE-2022-42890] Apache Batik information disclosure vulnerability www.openwall.com
text/html
URL Logo MLIST [oss-security] 20221025 [CVE-2022-42890] Apache Batik information disclosure vulnerability
Debian -- Security Information -- DSA-5264-1 batik www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-5264

Related QID Numbers

  • 150696 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2023)
  • 181174 Debian Security Update for batik (DLA 3169-1)
  • 181176 Debian Security Update for batik (DSA 5264-1)
  • 182666 Debian Security Update for batik (CVE-2022-42890)
  • 199377 Ubuntu Security Notification for Apache Batik Vulnerabilities (USN-6117-1)
  • 354806 Amazon Linux Security Advisory for batik : ALAS2-2023-1966
  • 354807 Amazon Linux Security Advisory for batik : ALAS-2023-1695
  • 355063 Amazon Linux Security Advisory for batik : AL2012-2023-387
  • 87546 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2023)

Exploit/POC from Github

This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationApacheBatikAllAllAllAll
Operating
System
DebianDebian Linux10.0AllAllAll
Operating
System
DebianDebian Linux11.0AllAllAll
  • cpe:2.3:a:apache:batik:*:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:

Discovery Credit

This issue was independently reported by Y4tacker and 4ra1n of Chaitin Tech

Social Mentions

Source Title Posted (UTC)
Twitter Icon @oss_security [CVE-2022-42890] Apache Batik information disclosure vulnerability: Posted by Simon Steiner on Oct 25CVE-2022-42890… twitter.com/i/web/status/1… 2022-10-25 13:25:35
Twitter Icon @CVEreport CVE-2022-42890 : A vulnerability in Batik of #Apache XML Graphics allows an attacker to run Java code from untruste… twitter.com/i/web/status/1… 2022-10-25 16:54:04
Twitter Icon @Robo_Alerts Potentially Critical CVE Detected! CVE-2022-42890 A vulnerability in Batik of Apache XML Graphics allows an attacke… twitter.com/i/web/status/1… 2022-10-25 18:56:00
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report