Bugzilla – Bug 1204704
VUL-0: CVE-2022-41704: xmlgraphics-batik: Apache Batik information disclosure vulnerability
Last modified: 2023-01-02 17:53:56 UTC
CVE-2022-41704 Posted by Simon Steiner on Oct 25CVE-2022-41704: Apache Batik information disclosure vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Batik 1.0 - 1.15 Description: Block loading jars by default to avoid running untrusted code Mitigation: Users should upgrade to Batik 1.16+ Credit: This issue was independently reported by Y4tacker and 4ra1n of Chaitin Tech and pwnull References:... References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41704 https://seclists.org/oss-sec/2022/q4/42