An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dompdf Project
Dompdf Project dompdf |
|
CPEs | cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dompdf Project
Dompdf Project dompdf |
Mon, 18 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dompdf
Dompdf dompdf |
|
CPEs | cpe:2.3:a:dompdf:dompdf:*:beta3:*:*:*:*:*:* | |
Vendors & Products |
Dompdf
Dompdf dompdf |
|
Metrics |
cvssV3_1
|
Fri, 15 Nov 2024 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks. | |
Title | Improper Restriction of XML External Entity Reference in dompdf/dompdf | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-11-15T10:52:10.986Z
Updated: 2024-11-18T14:35:29.986Z
Reserved: 2021-10-24T23:38:52.192Z
Link: CVE-2021-3902
Vulnrichment
Updated: 2024-11-18T14:34:14.547Z
NVD
Status : Analyzed
Published: 2024-11-15T11:15:06.190
Modified: 2024-11-19T17:12:15.650
Link: CVE-2021-3902
Redhat
No data.