CVE-2022-44729
Summary
| CVE | CVE-2022-44729 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 19:16:00 UTC |
| Updated | 2024-01-07 11:15:00 UTC |
| Description | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150735 Oracle WebLogic Server Multiple Vulnerabilities (CPU - OCT2023)
- 20366 Oracle Database 19c Critical Patch Update - October 2023
- 20367 Oracle Database 21c Critical Patch Update - October 2023
- 20368 Oracle Database 19c Critical OJVM Patch Update - October 2023
- 379090 IBM QRadar SIEM Multiple Security Vulnerabilities (7070736)
- 6000250 Debian Security Update for batik (DLA 3619-1)
- 710829 Gentoo Linux Apache Batik Multiple Vulnerabilities (GLSA 202401-11)
- 755916 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0777-1)
- 755935 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0808-1)
- 87548 Oracle WebLogic Server Multiple Vulnerabilities (CPUOCT2023)
- 994981 Java (Maven) Security Update for org.apache.xmlgraphics:batik-bridge (GHSA-gq5f-xv48-2365)