Code Injection in Batik XML - CVE-2022-41704

 

Code Injection in Batik XML - CVE-2022-41704

Published: October 30, 2022


Vulnerability identifier: #VU68826
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41704
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure processing links to .jar files inside .svg images. A remote attacker can upload a malicious .svg image that contains links to .jar files and execute arbitrary Java code on the system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Code injection example:

<script type="application/java-archive" xlink:href="file.jar"/>


Affected software

Batik XML
Amazon Linux AMI
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
Ubuntu
Development Tools Module
openSUSE Leap
openEuler
IBM Business Automation Workflow
Confluence Data Center
Jira Software Data Center
Confluence Server
Jira Software Server
IBM Case Manager
IBM Qradar SIEM
libbatik-java (Ubuntu package)
batik
batik-help
batik (Debian package)
dev-java/batik
xmlgraphics-batik
xmlgraphics-batik-ttf2svg
xmlgraphics-batik-demo
xmlgraphics-batik-css
xmlgraphics-batik-rasterizer
xmlgraphics-batik-slideshow
xmlgraphics-batik-javadoc
xmlgraphics-batik-squiggle
xmlgraphics-batik-svgpp
Red Hat Camel for Spring Boot
Fuse

How to mitigate CVE-2022-41704

Install updates from vendor's website.

Batik XML - update to 1.16
Confluence Data Center - update to 7.19.16
Confluence Server - update to 7.19.16
Jira Software Data Center - update to 9.4.16
Jira Software Server - update to 9.4.16
libbatik-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.14-1ubuntu0.2, 1.14-2ubuntu0.1
batik - update to 1.7-10.10
batik - update to 1.10-7
batik-help - update to 1.10-7
batik (Debian package) - update to 1.12-4+deb11u1
dev-java/batik - update to 1.17
xmlgraphics-batik - addressed in versions 1.17-2.7.1, 1.17-150200.4.7.1
xmlgraphics-batik-ttf2svg - update to 1.17-150200.4.7.1
xmlgraphics-batik-demo - update to 1.17-150200.4.7.1
xmlgraphics-batik-css - update to 1.17-150200.4.7.1
xmlgraphics-batik-rasterizer - update to 1.17-150200.4.7.1
xmlgraphics-batik-slideshow - update to 1.17-150200.4.7.1
xmlgraphics-batik-javadoc - update to 1.17-150200.4.7.1
xmlgraphics-batik-squiggle - update to 1.17-150200.4.7.1
xmlgraphics-batik-svgpp - update to 1.17-150200.4.7.1
Red Hat Camel for Spring Boot - update to 3.20.1
IBM Case Manager - update to 5.3.3-IF011
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Fuse - update to 7.12.0

External References

Related Security Bulletins