Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-73690
HistorySep 26, 2022 - 12:00 a.m.

Apache XML Graphics Batik Server-Side Request Forgery Vulnerability (CNVD-2022-73690)

2022-09-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
21
apache
xml
graphics
batik
ssrf
java
apache foundation
svg
vulnerable
server-side request forgery
flaw
fop
exploit
external resources
cnvd-2022-73690

EPSS

0.001

Percentile

51.4%

Apache XML Graphics Batik is a Java-based application from the Apache Foundation that is primarily used to process images in SVG format. Apache XML Graphics Batik is vulnerable to server-side request forgery, which is caused by a flaw when calling the fop function. An attacker could exploit the vulnerability to conduct an SSRF attack to obtain external resources.