CVE-2022-42890
Summary
| CVE | CVE-2022-42890 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-25 17:15:00 UTC |
| Updated | 2024-01-07 11:15:00 UTC |
| Description | A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Batik | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwly | MISC | lists.apache.org | |
| [SECURITY] [DLA 3169-1] batik security update | MLIST | lists.debian.org | |
| GLSA-202401-11 | security.gentoo.org | ||
| oss-security - [CVE-2022-42890] Apache Batik information disclosure vulnerability | MLIST | www.openwall.com | |
| Debian -- Security Information -- DSA-5264-1 batik | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: This issue was independently reported by Y4tacker and 4ra1n of Chaitin Tech
Legacy QID Mappings
- 150696 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2023)
- 181174 Debian Security Update for batik (DLA 3169-1)
- 181176 Debian Security Update for batik (DSA 5264-1)
- 182666 Debian Security Update for batik (CVE-2022-42890)
- 199377 Ubuntu Security Notification for Apache Batik Vulnerabilities (USN-6117-1)
- 354806 Amazon Linux Security Advisory for batik : ALAS2-2023-1966
- 354807 Amazon Linux Security Advisory for batik : ALAS-2023-1695
- 355063 Amazon Linux Security Advisory for batik : AL2012-2023-387
- 710829 Gentoo Linux Apache Batik Multiple Vulnerabilities (GLSA 202401-11)
- 730979 Atlassian Confluence Data Center and Server Multiple Vulnerabilities (CONFSERVER-93179,CONFSERVER-93178,CONFSERVER-93175)
- 731294 Atlassian Jira Software Data Center and Server Remote Code Execution (RCE) Vulnerability (JSWSERVER-25801)
- 755916 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0777-1)
- 755935 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0808-1)
- 87546 Oracle WebLogic Server Multiple Vulnerabilities (CPUJUL2023)