CVE-2022-44730
Summary
| CVE | CVE-2022-44730 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 19:16:00 UTC |
| Updated | 2024-01-07 11:15:00 UTC |
| Description | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
A malicious SVG can probe user profile / data and send it directly as parameter to a URL. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 379090 IBM QRadar SIEM Multiple Security Vulnerabilities (7070736)
- 6000250 Debian Security Update for batik (DLA 3619-1)
- 710829 Gentoo Linux Apache Batik Multiple Vulnerabilities (GLSA 202401-11)
- 755916 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0777-1)
- 755935 SUSE Enterprise Linux Security Update for xmlgraphics-batik (SUSE-SU-2024:0808-1)
- 994979 Java (Maven) Security Update for org.apache.xmlgraphics:batik-script (GHSA-2474-2566-3qxp)