Description
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
Remediation
References
https://lists.apache.org/thread/pkvhy0nsj1h1mlon008wtzhosbtxjwly
http://www.openwall.com/lists/oss-security/2022/10/25/3
https://lists.debian.org/debian-lts-announce/2022/10/msg00038.html
https://www.debian.org/security/2022/dsa-5264
https://security.gentoo.org/glsa/202401-11
Related Vulnerabilities
CVE-2017-4960 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2017-12621 Vulnerability in maven package commons-jelly:commons-jelly
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-43422 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-utilities
CVE-2018-1000013 Vulnerability in maven package org.jenkins-ci.plugins:release