CVE-2022-38648

MEDIUM5.3EPSS 0.22%

Apache Batik vulnerable to Server-Side Request Forgery

Published: 9/23/2022Modified: 4/28/2026

Description

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (9)