https://seclists.org/oss-sec/2023/q3/121: [CVE-2022-44730] Apache Batik information disclosure vulnerability
Published Aug 22, 2023
·Updated
Affected Software
1 affected component
Apache Batik>=1.0<=1.16
Frequently Asked Questions
1
What is the severity of CVE-2022-44730?
The severity of CVE-2022-44730 is classified as medium.
2
What versions of Apache Batik are affected by CVE-2022-44730?
CVE-2022-44730 affects Apache Batik versions 1.0 through 1.16.
3
What is the main issue addressed by CVE-2022-44730?
CVE-2022-44730 is an information disclosure vulnerability due to the switch to an empty whitelist for the Rhino scripting engine.
4
How do I fix CVE-2022-44730?
To fix CVE-2022-44730, update Apache Batik to a version above 1.16.
5
When was CVE-2022-44730 published?
CVE-2022-44730 was published on August 22, 2023.