Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35jj-wx47-4w8r

Опубликовано: 08 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

WeasyPrint allows the attachment of arbitrary files and URLs to a PDF

Impact

Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs.

Patches

Fixed by 734ee8e that’s included in 61.2

Workarounds

  • Check that no PDF attachment is defined in source HTML.
  • Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.

Пакеты

Наименование

weasyprint

pip
Затронутые версииВерсия исправления

>= 61.0, <= 61.1

61.2

EPSS

Процентиль: 32%
0.00123
Низкий

7.4 High

CVSS3

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 2 года назад

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.

CVSS3: 7.4
nvd
почти 2 года назад

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.

CVSS3: 7.4
debian
почти 2 года назад

WeasyPrint helps web developers to create PDF documents. Since version ...

EPSS

Процентиль: 32%
0.00123
Низкий

7.4 High

CVSS3

Дефекты

CWE-829