GHSA-53jm-3hc9-fqqc
Dashboard / Vulnerabilities / GHSA-53jm-3hc9-fqqc
Summary: Apache Batik vulnerable to Server-Side Request Forgery
Details: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik Bridge versions 1.14 and below.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-38648, https://github.com/apache/xmlgraphics-batik/commit/996aa8897c208be11ce65cef00c9576a299b2637, https://github.com/apache/xmlgraphics-batik, https://issues.apache.org/jira/browse/BATIK-1333, https://lists.apache.org/thread/gfsktxvj7jtwyovmhhbrw0bs13wfjd7b, https://lists.debian.org/debian-lts-announce/2023/10/msg00021.html, https://lists.debian.org/debian-lts-announce/2025/07/msg00006.html, https://security.gentoo.org/glsa/202401-11
Affected packages
Package
Name: org.apache.xmlgraphics:batik
Purl: pkg:maven/org.apache.xmlgraphics/batik
Affected ranges
Type: ECOSYSTEM
Events:
