CVE-2022-38648

MEDIUM

Apache XML Graphics Batik 1.14 - SSRF

Title source: llm
STIX 2.1

Description

Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 45.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-918
Status published
Products (4)
apache/batik 1.14
debian/debian_linux 10.0
org.apache.xmlgraphics/batik 0 - 1.15Maven
org.apache.xmlgraphics/batik-bridge 0 - 1.15Maven
Published Sep 22, 2022
Tracked Since Feb 18, 2026