Description
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0175 | Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application. |
Github GHSA |
GHSA-4q69-q4q7-x82c | rendertron can remotely shut down Chrome instance |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:20:50.740Z
Reserved: 2018-12-17T00:00:00.000Z
Link: CVE-2017-18353
No data.
Status : Modified
Published: 2018-12-17T07:29:00.327
Modified: 2024-11-21T03:19:54.637
Link: CVE-2017-18353
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA