CVE-2018-8013: Critical severity Apache Batik vulnerability
In Apache Batik 1.x before 1.10, when deserializing subclass of AbstractDocument, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.xmlgraphics:batikto a version that resolves this vulnerability.Fixed in 1.10 - Upgrade
Upgrade
debian/batikto a version that resolves this vulnerability.Fixed in 1.12-4+deb11u2Fixed in 1.12-4+deb11u3Fixed in 1.16+dfsg-1+deb12u1Fixed in 1.18+dfsg-2Fixed in 1.19-2
Event History
Frequently Asked Questions
What is CVE-2018-8013?
CVE-2018-8013 is a vulnerability in Apache Batik 1.x before 1.10 that allows for arbitrary code execution.
What is the severity of CVE-2018-8013?
CVE-2018-8013 has a severity rating of 9.8, which is considered critical.
How does CVE-2018-8013 affect Apache Batik?
CVE-2018-8013 affects versions of Apache Batik 1.x before 1.10.
How can I fix CVE-2018-8013?
To fix CVE-2018-8013, update Apache Batik to version 1.10 or later.
Where can I find more information about CVE-2018-8013?
You can find more information about CVE-2018-8013 on the Debian Security Tracker, MITRE CVE database, and Openwall mailing list.