Lucene search

K
cvelistApacheCVELIST:CVE-2022-42890
HistoryOct 25, 2022 - 12:00 a.m.

CVE-2022-42890 Apache Batik prior to 1.16 allows RCE via scripting

2022-10-2500:00:00
apache
www.cve.org
1
apache batik
rce
untrusted svg
apache xml graphics
javascript
upgrade

7.8 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.9%

A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache XML Graphics",
    "versions": [
      {
        "version": "Batik",
        "status": "affected",
        "lessThanOrEqual": "1.15",
        "versionType": "custom"
      }
    ]
  }
]