Description
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1385-1 | batik security update |
Debian DSA |
DSA-4215-1 | batik security update |
Github GHSA |
GHSA-25gw-4pcc-45cf | Deserialization of Untrusted Data in Apache Batik |
Ubuntu USN |
USN-3661-1 | Batik vulnerability |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apache
Subscribe
Batik
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Oracle
Subscribe
Business Intelligence
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Metasolv Solution
Subscribe
Communications Webrtc Session Controller
Subscribe
Data Integrator
Subscribe
Enterprise Repository
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Fusion Middleware Mapviewer
Subscribe
Instantis Enterprisetrack
Subscribe
Insurance Calculation Engine
Subscribe
Insurance Policy Administration J2ee
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Retail Back Office
Subscribe
Retail Central Office
Subscribe
Retail Integration Bus
Subscribe
Retail Order Broker
Subscribe
Retail Point-of-service
Subscribe
Retail Returns Management
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T23:16:36.073Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-8013
No data.
Status : Modified
Published: 2018-05-24T16:29:00.380
Modified: 2024-11-21T04:13:05.577
Link: CVE-2018-8013
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN