Описание
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| devel | not-affected | 0.12.6-2 |
| esm-apps/bionic | released | 0.12.4-1ubuntu0.1~esm1 |
| esm-apps/focal | released | 0.12.5-1ubuntu0.1 |
| esm-apps/jammy | not-affected | 0.12.6-2 |
| esm-apps/xenial | released | 0.12.2.4-1ubuntu0.1~esm1 |
| esm-infra-legacy/trusty | released | 0.9.9-4ubuntu0.1~esm1 |
| focal | released | 0.12.5-1ubuntu0.1 |
| jammy | not-affected | 0.12.6-2 |
| kinetic | not-affected | 0.12.6-2 |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows ...
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
Уязвимость утилиты командной строки для преобразования HTML-файлов в PDF формат wkhtmltopdf, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть конфиденциальную информацию
7.5 High
CVSS3