Skip to content

Upgrade batik version to 1.16 (#9718)#10722

Merged
coheigea merged 1 commit intocamel-3.xfrom
coheigea/xmlgraphics-1.16-camel-3.x
Jul 19, 2023
Merged

Upgrade batik version to 1.16 (#9718)#10722
coheigea merged 1 commit intocamel-3.xfrom
coheigea/xmlgraphics-1.16-camel-3.x

Conversation

@coheigea
Copy link
Contributor

Description

Backporting upgrade from main to fix:

org.apache.xmlgraphics:batik-bridge (batik-bridge-1.15.jar) │ CVE-2022-41704 │ │ 1.15 │ 1.16 │ Apache XML Graphics Batik vulnerable to code execution via │
│ │ │ │ │ │ SVG │
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-41704
├──────────────────────────────────────────────────────────────┤ │ │ │ │ │
│ org.apache.xmlgraphics:batik-dom (batik-dom-1.15.jar) │ │ │ │ │ │
│ │ │ │ │ │ │
│ │ │ │ │ │ │
│ ├────────────────┤ │ │ ├─────────────────────────────────────────────────────────────┤
│ │ CVE-2022-42890 │ │ │ │ Untrusted code execution in Apache XML Graphics Batik │
│ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-42890
├──────────────────────────────────────────────────────────────┤ │ │ │ │ │
│ org.apache.xmlgraphics:batik-script (batik-script-1.15.jar) │ │ │ │ │ │
│ │ │ │ │ │ │

I also intend to open PRs against 3.21.x + 3.20.x

@github-actions
Copy link
Contributor

🚫 There are (likely) no components to be tested in this PR

@github-actions
Copy link
Contributor

🚫 There are (likely) no changes in core core to be tested in this PR

@coheigea coheigea merged commit a8d0434 into camel-3.x Jul 19, 2023
@coheigea coheigea deleted the coheigea/xmlgraphics-1.16-camel-3.x branch July 19, 2023 10:58
coheigea added a commit that referenced this pull request Jul 19, 2023
Co-authored-by: Tom Cunningham <tcunning@redhat.com>
coheigea added a commit that referenced this pull request Jul 19, 2023
Co-authored-by: Tom Cunningham <tcunning@redhat.com>
coheigea added a commit that referenced this pull request Jul 19, 2023
Co-authored-by: Tom Cunningham <tcunning@redhat.com>
coheigea added a commit that referenced this pull request Jul 19, 2023
Co-authored-by: Tom Cunningham <tcunning@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants