Описание
This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.
Ссылки
- Broken LinkThird Party Advisory
- Third Party Advisory
- Broken LinkThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:node-pdf-generator_project:node-pdf-generator:*:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.0548
Низкий
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 8.2
github
больше 4 лет назад
Server-Side Request Forgery in node-pdf-generator
EPSS
Процентиль: 90%
0.0548
Низкий
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-20