A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3619-1 | batik security update |
Github GHSA |
GHSA-2474-2566-3qxp | Apache Batik information disclosure vulnerability |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL. | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL. |
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:33:42.755Z
Reserved: 2022-11-04T09:27:40.482Z
Link: CVE-2022-44730
No data.
Status : Modified
Published: 2023-08-22T19:16:29.930
Modified: 2025-02-13T17:15:47.057
Link: CVE-2022-44730
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA