Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-35583

Опубликовано: 22 авг. 2022
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 9.8

Описание

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/bionic

deferred

2023-07-18
esm-apps/focal

deferred

2023-07-18
esm-apps/jammy

deferred

2023-07-18
esm-apps/noble

deferred

2023-07-18
esm-apps/xenial

deferred

2023-07-18
esm-infra-legacy/trusty

deferred

2023-07-18
focal

ignored

end of standard support, was deferred [2023-07-18]
jammy

deferred

2023-07-18

Показывать по

EPSS

Процентиль: 98%
0.58883
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

CVSS3: 9.8
debian
больше 3 лет назад

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to g ...

CVSS3: 9.8
github
больше 3 лет назад

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

EPSS

Процентиль: 98%
0.58883
Средний

9.8 Critical

CVSS3