Bugzilla – Bug 1203674
VUL-0: CVE-2022-38398: xmlgraphics-batik: information disclosure vulnerability
Last modified: 2022-10-10 16:49:19 UTC
CVE-2022-38398 Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-38398 https://seclists.org/oss-sec/2022/q3/221 https://www.cve.org/CVERecord?id=CVE-2022-38398 https://lists.apache.org/thread/712c9xwtmyghyokzrm2ml6sps4xlmbsx
Thanks Robert for your report. I'm no longer maintainer or bugowner for Java related packages. This is done by Fridrich Strba now. Thanks Fridrich for taking over!
tracking as affected: - SUSE:SLE-15-SP2:Update/xmlgraphics-batik