Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-35583

Опубликовано: 22 авг. 2022
Источник: debian
EPSS Средний

Описание

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wkhtmltopdfunfixedpackage

Примечания

  • https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silently

  • https://github.com/wkhtmltopdf/wkhtmltopdf/issues/5249

  • By design, wkhtmltopdf retrieves external resources. If it is employed inside

  • a protected network in an automated way, a malicious actor may access internal

  • resources. A user of wkhtmltopdf should restrict such access.

EPSS

Процентиль: 98%
0.56422
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

CVSS3: 9.8
nvd
больше 3 лет назад

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

CVSS3: 9.8
github
больше 3 лет назад

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

EPSS

Процентиль: 98%
0.56422
Средний