Описание
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as .
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00213
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
Server-side Request Forgery in github.com/thecodingmachine/gotenberg
EPSS
Процентиль: 44%
0.00213
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-918