An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.
History

Tue, 19 Nov 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Dompdf Project
Dompdf Project dompdf
CPEs cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:*
Vendors & Products Dompdf Project
Dompdf Project dompdf

Mon, 18 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Dompdf
Dompdf dompdf
CPEs cpe:2.3:a:dompdf:dompdf:*:beta3:*:*:*:*:*:*
Vendors & Products Dompdf
Dompdf dompdf
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 11:00:00 +0000

Type Values Removed Values Added
Description An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.
Title Improper Restriction of XML External Entity Reference in dompdf/dompdf
Weaknesses CWE-611
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-11-15T10:52:10.986Z

Updated: 2024-11-18T14:35:29.986Z

Reserved: 2021-10-24T23:38:52.192Z

Link: CVE-2021-3902

cve-icon Vulnrichment

Updated: 2024-11-18T14:34:14.547Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-15T11:15:06.190

Modified: 2024-11-19T17:12:15.650

Link: CVE-2021-3902

cve-icon Redhat

No data.