Bug 2233899 (CVE-2022-44730)
| Summary: | CVE-2022-44730 batik: Server-Side Request Forgery vulnerability | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | adupliak, aileenc, alampare, alazarot, almacdon, asoldano, bbaranow, bmaxwell, brian.stansberry, cdewolf, chazlett, cmiranda, darran.lofthouse, desktop-qa-list, dhanak, dkreling, dosoudil, emingora, fjuma, fmariani, gjospin, gmalinko, ibek, ivassile, iweiss, janstey, jkang, jpoth, jrokos, jvanek, kverlaen, lbacciot, lgao, mizdebsk, mnovotny, mosmerov, msochure, mstefank, msvehla, nwallace, pcongius, pdelbell, peholase, pjindal, pmackay, rguimara, rstancel, saroy, smaestri, tcunning, tom.jenkinson, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | batik 1.17 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in Apache Batik, where a malicious SVG can probe user profile data and send it directly as parameter to a URL. This issue can allow an attacker to conduct SSRF attacks.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2233902, 2233903, 2234660, 2234661 | ||
| Bug Blocks: | 2233900 | ||
|
Description
Guilherme de Almeida Suckevicz
2023-08-23 16:34:22 UTC
Versions Affected: Batik 1.0 - 1.16 References: https://issues.apache.org/jira/browse/BATIK-1347 https://github.com/advisories/GHSA-2474-2566-3qxp https://github.com/apache/xmlgraphics-batik/commit/f9ae69233eadfbd392a4a08a55618f97343b467c Created batik tracking bugs for this issue: Affects: fedora-all [bug 2234660] This issue has been addressed in the following products: RHINT Camel-Springboot 4.0.0 Via RHSA-2023:5441 https://access.redhat.com/errata/RHSA-2023:5441 This issue has been addressed in the following products: RHPAM 7.13.5 async Via RHSA-2024:1353 https://access.redhat.com/errata/RHSA-2024:1353 |