Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-577p-7j7h-2jgf

Опубликовано: 15 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Deserialization of Untrusted Data in dompdf/dompdf

DomPDF before version 2.0.0 is vulnerable to PHAR (PHP Archive) deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

Пакеты

Наименование

dompdf/dompdf

composer
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 87%
0.03372
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

CVSS3: 9.8
nvd
около 1 года назад

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

CVSS3: 9.8
debian
около 1 года назад

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due ...

EPSS

Процентиль: 87%
0.03372
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502