CVE-2022-40146
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
- Affected products
- Apache Xml Graphics Batik, Astra Linux, Confluence, Debian, Jira, Linuxmint, Suse, Ubuntu
- Apache Batik
- = 1.14
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 6.1% (93th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2022-09-22
CVE-2022-40146 at NVD
1 known exploit for CVE-2022-40146
Proof-of-concept code and exploit modules indexed by Sploitus