major
minor
major
minor
Currently, version 1.15 of the Apache Batik library is in use.
This version contains several security vulnerabilities:
A vulnerability in Batik, part of Apache XML Graphics, allows an attacker to execute Java code from an untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to version 1.16. Users are advised to upgrade to version 1.16.
A vulnerability in Batik, part of Apache XML Graphics, allows an attacker to execute untrusted Java code from an SVG file. This issue affects versions of Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.
Details can be found here.
Test
The CheckDependencies build task should not contain any errors of the type “com.top-logic:tl-parent-all.pkg:maven/org.apache.xmlgraphics/batik-bridge@1.15.”