Описание
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
An XXE vulnerability was found in Apache Batik which could allow a remote attacker to retrieve the files on the vulnerable server's filesystem by uploading specially crafted SVG images. The vulnerability could also allow a denial of service condition by performing an amplification attack.
Отчет
The batik package is no longer used or required by the Red Hat Virtualization Manager. Red Hat recommends removing it after updating to Red Hat Virtualization 4.1.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | batik | Will not fix | ||
| Red Hat Enterprise Linux 7 | batik | Will not fix | ||
| Red Hat JBoss Fuse Service Works 6 | batik | Will not fix | ||
| Red Hat Software Collections | rh-java-common-batik | Will not fix | ||
| Red Hat Virtualization 4 | batik | Affected | ||
| Red Hat JBoss A-MQ 6.3 | switchyard | Fixed | RHSA-2018:0319 | 14.02.2018 |
| Red Hat JBoss BPMS 6.4 | batik | Fixed | RHSA-2017:2546 | 29.08.2017 |
| Red Hat JBoss BRMS 6.4 | batik | Fixed | RHSA-2017:2547 | 29.08.2017 |
| Red Hat JBoss Fuse 6.3 | switchyard | Fixed | RHSA-2018:0319 | 14.02.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
In Apache Batik before 1.9, files lying on the filesystem of the serve ...
Improper Restriction of XML External Entity Reference in Apache Batik
EPSS
7.5 High
CVSS3