The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0151 The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
Github GHSA Github GHSA GHSA-27p5-7cw6-m45h Server-Side Request Forgery in unoconv
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:40:15.443Z

Reserved: 2019-10-09T00:00:00

Link: CVE-2019-17400

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-21T23:15:12.183

Modified: 2024-11-21T04:32:16.003

Link: CVE-2019-17400

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-10-21T00:00:00Z

Links: CVE-2019-17400 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses