Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3838

Опубликовано: 15 нояб. 2024
Источник: debian
EPSS Низкий

Описание

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-dompdffixed2.0.2+dfsg-1package

Примечания

  • https://github.com/dompdf/dompdf/issues/2564

  • https://huntr.dev/bounties/0bdddc12-ff67-4815-ab9f-6011a974f48e

  • https://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439e7ee0bb6a (v2.0.0)

EPSS

Процентиль: 87%
0.03372
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

CVSS3: 9.8
nvd
около 1 года назад

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

CVSS3: 9.8
github
около 1 года назад

Deserialization of Untrusted Data in dompdf/dompdf

EPSS

Процентиль: 87%
0.03372
Низкий