CVE-2017-5662: XEE
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.10-2+deb10u1Fixed in 1.10-2+deb10u3Fixed in 1.12-4+deb11u2Fixed in 1.12-4+deb11u1Fixed in 1.16+dfsg-1+deb12u1Fixed in 1.17+dfsg-1 - Upgrade
Upgrade
redhat/batikto a version that resolves this vulnerability.Fixed in 1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5662?
CVE-2017-5662 has a moderate severity rating due to its ability to expose sensitive files on the server to unauthorized users.
How do I fix CVE-2017-5662?
To remediate CVE-2017-5662, upgrade Apache Batik to version 1.9 or later to mitigate the vulnerability.
What types of files can be leaked due to CVE-2017-5662?
The types of files that can be revealed through CVE-2017-5662 depend on the permissions of the user context running the vulnerable application.
Which versions of Apache Batik are affected by CVE-2017-5662?
All versions of Apache Batik before 1.9 are vulnerable to CVE-2017-5662.
Is there a known exploit for CVE-2017-5662?
Yes, CVE-2017-5662 can be exploited by sending specially crafted SVG files to the affected application.