Описание
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
Ссылки
- Patch
- Vendor Advisory
- Mailing ListThird Party Advisory
- Patch
- Vendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
EPSS
7.4 High
CVSS3
Дефекты
Связанные уязвимости
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
WeasyPrint helps web developers to create PDF documents. Since version ...
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
EPSS
7.4 High
CVSS3