Bugzilla – Bug 1203674
VUL-0: CVE-2022-38398: xmlgraphics-batik: information disclosure vulnerability
Last modified: 2024-04-19 14:14:44 UTC
CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-38398 https://seclists.org/oss-sec/2022/q3/221 https://www.cve.org/CVERecord?id=CVE-2022-38398 https://lists.apache.org/thread/712c9xwtmyghyokzrm2ml6sps4xlmbsx
Thanks Robert for your report. I'm no longer maintainer or bugowner for Java related packages. This is done by Fridrich Strba now. Thanks Fridrich for taking over!
tracking as affected: - SUSE:SLE-15-SP2:Update/xmlgraphics-batik
SUSE-SU-2024:0777-1: An update that solves 10 vulnerabilities can now be installed. Category: security (important) Bug References: 1034675, 1172961, 1182748, 1203672, 1203673, 1203674, 1204704, 1204709 CVE References: CVE-2017-5662, CVE-2019-17566, CVE-2020-11987, CVE-2022-38398, CVE-2022-38648, CVE-2022-40146, CVE-2022-41704, CVE-2022-42890, CVE-2022-44729, CVE-2022-44730 Sources used: SUSE Linux Enterprise Software Development Kit 12 SP5 (src): xmlgraphics-batik-1.17-2.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Despise the bot not mentioning the SLE-15-SP2 release of today, this can be considered as closed. Reassigning to security.
done