You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Improper restriction of external entities (XXE) in DomPDF's SVG parser allows it to perform an SSRF even if isRemoteEnabled set to false or even cause a deserialization attack in the SVG parser this time. The issue is patched in version 2.0.0.
CVE-2021-3902 - Critical Severity Vulnerability
DOMPDF is a CSS 2.1 compliant HTML to PDF converter
Library home page: https://api.github.com/repos/dompdf/dompdf/zipball/8768448244967a46d6e67b891d30878e0e15d25c
Dependency Hierarchy:
Found in HEAD commit: 928b87c3f458bb28df552e1c49bfeb1231a16bcf
Found in base branch: main
Improper restriction of external entities (XXE) in DomPDF's SVG parser allows it to perform an SSRF even if isRemoteEnabled set to false or even cause a deserialization attack in the SVG parser this time. The issue is patched in version 2.0.0.
Publish Date: 2021-10-25
URL: CVE-2021-3902
Base Score Metrics:
Type: Upgrade version
Origin: https://huntr.dev/bounties/a6071c07-806f-429a-8656-a4742e4191b1/
Release Date: 2021-10-25
Fix Resolution: v2.0.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: