[CVE-2022-38398] Apache Batik information disclosure vulnerability

"Simon Steiner" <[email protected]>
Newsgroups gmane.comp.security.oss.general,gmane.text.xml.general,gmane.text.xml.batik.devel,gmane.text.xml.batik.user
Message-ID <[email protected]>
CVE-2022-38398:
        Apache Batik information disclosure vulnerability

Severity:
        Medium

Vendor:
        The Apache Software Foundation

Versions Affected:
        Batik 1.0 - 1.14

Description:
        DefaultExternalResourceSecurity should block urls loaded thru the
jar protocol

Mitigation:
        Users should upgrade to Batik 1.15+

Credit:
        This issue was independently reported by Piotr Bazydlo (@chudypb) of
Trend Micro Zero Day Initiative

References:
        http://xmlgraphics.apache.org/security.html
        https://issues.apache.org/jira/browse/BATIK-1331

The Apache XML Graphics team.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.