Описание
xml2rfc has an arbitrary file read vulnerability
Impact
When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the XML.
Workarounds
Test untrusted input with link elements with rel="attachment" before processing.
Credits
This vulnerability was reported by Mohamed Ouad from Doyensec.
Пакеты
Наименование
xml2rfc
pip
Затронутые версииВерсия исправления
<= 3.30.0
3.30.1