Bugzilla – Bug 1204709
VUL-0: CVE-2022-42890: xmlgraphics-batik: Apache Batik information disclosure vulnerability
Last modified: 2023-01-02 17:53:39 UTC
CVE-2022-42890 Posted by Simon Steiner on Oct 25CVE-2022-42890: Apache Batik information disclosure vulnerability Severity: Medium Vendor: The Apache Software Foundation Versions Affected: Batik 1.0 - 1.15 Description: Restrict what java classes can be run thru JavaScript Mitigation: Users should upgrade to Batik 1.16+ Credit: This issue was independently reported by Y4tacker and 4ra1n of Chaitin Tech References:... References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-42890 https://seclists.org/oss-sec/2022/q4/43