GHSA-wfw6-mmmp-87xm

Suggest an improvement
Source
https://github.com/advisories/GHSA-wfw6-mmmp-87xm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wfw6-mmmp-87xm/GHSA-wfw6-mmmp-87xm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wfw6-mmmp-87xm
Aliases
Published
2022-05-17T00:28:34Z
Modified
2023-11-08T03:57:48.044518Z
Summary
Improper Input Validation in Apache Batik
Details

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

Database specific
{
    "nvd_published_at": "2015-03-24T17:59:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-07-06T20:29:14Z"
}
References

Affected packages

Maven / org.apache.xmlgraphics:batik

Package

Name
org.apache.xmlgraphics:batik
View open source insights on deps.dev
Purl
pkg:maven/org.apache.xmlgraphics/batik

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0
Fixed
1.8