CVE-2020-18972
published 2021-08-25CVE-2020-18972: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.76%
51.8th percentile
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpodofo | — | — |
| podofo_project | podofo | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-18972: libpodofo - Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allo...
vendor_debian·2020·CVSS 5.5
CVE-2020-18972 [MEDIUM] CVE-2020-18972: libpodofo - Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allo...
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-x4h7-rg57-2fqw: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0
ghsa_unreviewed·2022-05-24
CVE-2020-18972 [MEDIUM] CWE-668 GHSA-x4h7-rg57-2fqw: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
OSV
CVE-2020-18972: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0
osv·2021-08-25·CVSS 5.5
CVE-2020-18972 [MEDIUM] CVE-2020-18972: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-25
Published