CVE-2022-42890
Untrusted code execution in Apache XML Graphics Batik
7.5
HIGH
CVSS 3.1
EPSS 0.54%
Description
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16.
How to fix CVE-2022-42890
To remediate CVE-2022-42890, upgrade the affected package to a fixed version below.
- Debian/batik—upgrade to 1.12-4+deb11u1 or later
- —upgrade to 1.16 or later
- —upgrade to 1.16 or later
Is CVE-2022-42890 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.12-4+deb11u1
- from 0, < 1.16
- from 0, < 1.16
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |