Bug 2233889 (CVE-2022-44729)
| Summary: | CVE-2022-44729 batik: Server-Side Request Forgery vulnerability | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | adupliak, aileenc, alazarot, almacdon, asoldano, bbaranow, bmaxwell, brian.stansberry, chazlett, cmiranda, darran.lofthouse, desktop-qa-list, dhanak, dkreling, dosoudil, emingora, fmariani, gjospin, gmalinko, ibek, ivassile, iweiss, janstey, jkang, jpoth, jrokos, jvanek, kverlaen, lbacciot, lgao, mizdebsk, mnovotny, mosmerov, msochure, mstefank, msvehla, nwallace, pcongius, pdelbell, peholase, pjindal, pmackay, rguimara, rstancel, saroy, smaestri, tcunning, tom.jenkinson, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | batik 1.17 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in Apache Batik 1.0 - 1.16. This issue occurs due to a malicious SVG triggering external resources loading by default, causing resource consumption or in some cases information disclosure.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2233904, 2234660, 2234661 | ||
| Bug Blocks: | 2233900 | ||
|
Description
Guilherme de Almeida Suckevicz
2023-08-23 16:28:57 UTC
Versions Affected: Batik 1.0 - 1.16 References: https://issues.apache.org/jira/browse/BATIK-1349 https://github.com/advisories/GHSA-gq5f-xv48-2365 https://github.com/apache/xmlgraphics-batik/commit/85b3457d9902f64d5d409a8da060d5ba47d0b69b https://github.com/apache/xmlgraphics-batik/commit/aaa1dd3e6b5a7df781d73e0c37a1df6a8f318893 Created batik tracking bugs for this issue: Affects: fedora-all [bug 2234660] This issue has been addressed in the following products: RHINT Camel-Springboot 4.0.0 Via RHSA-2023:5441 https://access.redhat.com/errata/RHSA-2023:5441 This issue has been addressed in the following products: RHPAM 7.13.5 async Via RHSA-2024:1353 https://access.redhat.com/errata/RHSA-2024:1353 |