Описание
Snappy : SSRF and local file read via the xsl-style-sheet option
Impact
It impacts applications where:
- the PHP daemon run with root permissions ;
- the application is either running outside a container or has sensitive file access ;
It could happens with this kind of workflows:
Patches
A list a schema with http and https by default is used to validate the remote path by default.
Workarounds
Developers should ensure usage cannot allow (in any case) a user to pass a free input directly to the Snappy library.
Instead developers can list available available stylesheets and pick the right one with the user input.
References
Read more about SSRF at owasp.org/www-community/attacks/Server_Side_Request_Forgery
Пакеты
knplabs/knp-snappy
<= 1.6.0
1.7.0
Связанные уязвимости
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet option. This issue has been patched in version 1.7.0.
Snappy: SSRF and local file read via the xsl-style-sheet option