CVE-2022-44729

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.

On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
apachexml_graphics_batik
1.0 ≤
𝑥
≤ 1.16
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
batik
bookworm
1.16+dfsg-1+deb12u1
fixed
bullseye
1.12-4+deb11u2
fixed
bullseye (security)
vulnerable
sid
1.18+dfsg-2
fixed
trixie
1.18+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
batik
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
ignored
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
xmlgraphics-batik
suse enterprise desktop 15 SP5
1.17-150200.4.7.1
fixed
suse enterprise sap 15 SP5
1.17-150200.4.7.1
fixed
suse enterprise server 15 SP5
1.17-150200.4.7.1
fixed
xmlgraphics-batik-css
suse enterprise desktop 15 SP5
1.17-150200.4.7.1
fixed
suse enterprise sap 15 SP5
1.17-150200.4.7.1
fixed
suse enterprise server 15 SP5
1.17-150200.4.7.1
fixed