Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfpx-3hgc-pc2g

Опубликовано: 17 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Gotenberg provides a developer-friendly API to interact with powerful tools like Chromium and LibreOffice for converting numerous document formats (HTML, Markdown, Word, Excel, etc.) into PDF files, and more! Prior to version 8.1.0, the default value for the flag --chromium-deny-list allowed to display some internal files from the Gotenberg container. Version 8.1.0 provides a new default value fixing the issue. Prior to version 8.1.0, Gotenberg uses the standard regexp Go library, which does not support negative lookahead. Therefore, the new default value for the --chromium-deny-list is not applicable. However, one could find an alternative using either or both --chromium-deny-list and --chromium-allow-list flags. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Gotenberg provides a developer-friendly API to interact with powerful tools like Chromium and LibreOffice for converting numerous document formats (HTML, Markdown, Word, Excel, etc.) into PDF files, and more! Prior to version 8.1.0, the default value for the flag --chromium-deny-list allowed to display some internal files from the Gotenberg container. Version 8.1.0 provides a new default value fixing the issue. Prior to version 8.1.0, Gotenberg uses the standard regexp Go library, which does not support negative lookahead. Therefore, the new default value for the --chromium-deny-list is not applicable. However, one could find an alternative using either or both --chromium-deny-list and --chromium-allow-list flags. Users are advised to upgrade. There are no known workarounds for this vulnerability.

8.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 1 года назад

Rejected reason: This CVE is a duplicate of another CVE.

8.2 High

CVSS3

Дефекты

CWE-200