[MAVEN:GHSA-C5XV-QC8P-MH2V] Apache Batik Server-Side Request Forgery

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.

Package Affected Version
pkg:maven/org.apache.xmlgraphics/batik >= 1.0, < 1.15
Package Fixed Version
pkg:maven/org.apache.xmlgraphics/batik = 1.15
ID
MAVEN:GHSA-C5XV-QC8P-MH2V
Severity
moderate
URL
https://github.com/advisories/GHSA-c5xv-qc8p-mh2v
Published
2022-09-23T00:00:39
(2 years ago)
Modified
2024-01-08T15:35:15
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.xmlgraphics/batik org.apache.xmlgraphics batik >= 1.0 < 1.15
Fixed pkg:maven/org.apache.xmlgraphics/batik org.apache.xmlgraphics batik = 1.15
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...