A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3169-1 | batik security update |
Debian DSA |
DSA-5264-1 | batik security update |
Github GHSA |
GHSA-r29w-r9ph-vm76 | Apache XML Graphics Batik vulnerable to code execution via SVG. |
Ubuntu USN |
USN-6117-1 | Apache Batik vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T12:49:44.004Z
Reserved: 2022-09-28T00:00:00
Link: CVE-2022-41704
No data.
Status : Modified
Published: 2022-10-25T17:15:57.527
Modified: 2024-11-21T07:23:41.227
Link: CVE-2022-41704
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN