Bug 2233889 (CVE-2022-44729)
Summary: | CVE-2022-44729 batik: Server-Side Request Forgery vulnerability | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | adupliak, aileenc, alampare, alazarot, almacdon, asoldano, bbaranow, bmaxwell, brian.stansberry, cdewolf, chazlett, cmiranda, darran.lofthouse, desktop-qa-list, dhanak, dkreling, dosoudil, emingora, fjuma, fmariani, gjospin, gmalinko, ibek, ivassile, iweiss, janstey, jkang, jpoth, jrokos, jvanek, kverlaen, lbacciot, lgao, mizdebsk, mnovotny, mosmerov, msochure, mstefank, msvehla, nwallace, pcongius, pdelbell, peholase, pjindal, pmackay, rguimara, rstancel, saroy, smaestri, tcunning, tom.jenkinson, yfang |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | batik 1.17 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in Apache Batik 1.0 - 1.16. This issue occurs due to a malicious SVG triggering external resources loading by default, causing resource consumption or in some cases information disclosure.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2233904, 2234660, 2234661 | ||
Bug Blocks: | 2233900 |
Description
Guilherme de Almeida Suckevicz
2023-08-23 16:28:57 UTC
Versions Affected: Batik 1.0 - 1.16 References: https://issues.apache.org/jira/browse/BATIK-1349 https://github.com/advisories/GHSA-gq5f-xv48-2365 https://github.com/apache/xmlgraphics-batik/commit/85b3457d9902f64d5d409a8da060d5ba47d0b69b https://github.com/apache/xmlgraphics-batik/commit/aaa1dd3e6b5a7df781d73e0c37a1df6a8f318893 Created batik tracking bugs for this issue: Affects: fedora-all [bug 2234660] This issue has been addressed in the following products: RHINT Camel-Springboot 4.0.0 Via RHSA-2023:5441 https://access.redhat.com/errata/RHSA-2023:5441 This issue has been addressed in the following products: RHPAM 7.13.5 async Via RHSA-2024:1353 https://access.redhat.com/errata/RHSA-2024:1353 |