Описание
TCPDF missing certificate validation
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
Пакеты
Наименование
tecnickcom/tcpdf
composer
Затронутые версииВерсия исправления
< 6.8.0
6.8.0
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 1 года назад
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
CVSS3: 9.8
nvd
около 1 года назад
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
CVSS3: 9.8
debian
около 1 года назад
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CUR ...