
====================================================================

                             CERT-Renater

                 Note d'Information No. 2020/VULN355
_____________________________________________________________________

DATE                : 18/06/2020

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Batik versions prior to 1.12.

=====================================================================
http://mail-archives.apache.org/mod_mbox/xmlgraphics-batik-users/202006.mbox/%3c001201d642f3$0ab3ccd0$201b6670$@gmail.com%3e
_____________________________________________________________________

CVE-2019-17566:
        Apache XML Graphics Batik SSRF vulnerability

Severity:
        Medium

Vendor:
        The Apache Software Foundation

Versions Affected:
        Batik 1.12 and earlier

Description:
        The Apache Batik library is vulnerable to SSRF via "xlink:href"
attributes that allow an
attacker to cause the underlying server to make arbitrary GET requests.

Mitigation:
        Users should upgrade to Batik 1.13 or later and pass
-blockExternalResources on the command line

Credit:
        This issue was independently reported by Sean Melia

References:
        http://xmlgraphics.apache.org/security.html

The Apache XML Graphics team.

=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================



