Description
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3619-1 | batik security update |
Debian DLA |
DLA-4243-1 | batik security update |
Github GHSA |
GHSA-c5xv-qc8p-mh2v | Apache Batik Server-Side Request Forgery |
Ubuntu USN |
USN-6117-1 | Apache Batik vulnerabilities |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-03T19:27:24.506Z
Reserved: 2022-08-18T00:00:00.000Z
Link: CVE-2022-38398
No data.
Status : Modified
Published: 2022-09-22T15:15:09.287
Modified: 2025-11-03T20:15:56.057
Link: CVE-2022-38398
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA
Ubuntu USN