Lucene search

K
cvelistApacheCVELIST:CVE-2022-44730
HistoryAug 22, 2023 - 1:57 p.m.

CVE-2022-44730 Apache XML Graphics Batik: Information disclosure vulnerability

2023-08-2213:57:00
CWE-918
apache
www.cve.org
2
apache
xml graphics batik
ssrf
vulnerability
version 1.16

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.8%

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.

A malicious SVG can probe user profile / data and send it directly as parameter to a URL.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache XML Graphics Batik",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "1.16"
      }
    ]
  }
]

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.8%