Описание
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
Ссылки
- Patch
- Vendor AdvisoryMitigationPatch
Уязвимые конфигурации
Конфигурация 1Версия до 2.94.0 (исключая)
cpe:2.3:a:docling:docling:*:*:*:*:*:python:*:*
EPSS
Процентиль: 12%
0.00217
Низкий
7.1 High
CVSS3
Дефекты
CWE-73
Связанные уязвимости
CVSS3: 7.1
redhat
около 1 месяца назад
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0.
CVSS3: 7.1
github
2 месяца назад
Docling: Unsafe URI and Path Handling in HTML Backend
EPSS
Процентиль: 12%
0.00217
Низкий
7.1 High
CVSS3
Дефекты
CWE-73