https://seclists.org/oss-sec/2023/q3/118: [CVE-2022-44729] Apache Batik information disclosure vulnerability
Published Aug 22, 2023
·Updated
Affected Software
1 affected component
Apache Batik>=1.0<=1.16
Frequently Asked Questions
1
What is the severity of CVE-2022-44729?
The severity of CVE-2022-44729 is rated as Medium.
2
Which versions of Apache Batik are affected by CVE-2022-44729?
Apache Batik versions 1.0 through 1.16 are affected by CVE-2022-44729.
3
How do I fix CVE-2022-44729?
To fix CVE-2022-44729, users should upgrade Apache Batik to version 1.17 or later.
4
What type of vulnerability is CVE-2022-44729?
CVE-2022-44729 is classified as an information disclosure vulnerability.
5
What is the default behavior regarding external resources in Apache Batik affected by CVE-2022-44729?
By default, Apache Batik was blocking the loading of external resources prior to the fix in version 1.17.