CVE-2022-2400
published 2022-07-18CVE-2022-2400: External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.91%
55.6th percentile
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php-dompdf | < php-dompdf 2.0.2+dfsg-1 (bookworm) | php-dompdf 2.0.2+dfsg-1 (bookworm) |
| dompdf | dompdf | >= 0 < 2.0.0 | 2.0.0 |
| dompdf | dompdf_dompdf | >= unspecified < 2.0.0 | 2.0.0 |
| dompdf_project | dompdf | < 2.0.0 | 2.0.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dompdf vulnerabilities
vendor_ubuntu·2023-08-10·CVSS 6.5
CVE-2021-3838 [MEDIUM] Dompdf vulnerabilities
Title: Dompdf vulnerabilities
Summary: Several security issues were fixed in Dompdf.
USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the
corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021
Ubuntu
Dompdf vulnerabilities
vendor_ubuntu·2023-08-08·CVSS 6.5
CVE-2014-5011 [MEDIUM] Dompdf vulnerabilities
Title: Dompdf vulnerabilities
Summary: Several security issues were fixed in Dompdf.
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced both a remote base and a local file,
Debian
CVE-2022-2400: php-dompdf - External Control of File Name or Path in GitHub repository dompdf/dompdf prior t...
vendor_debian·2022·CVSS 5.3
CVE-2022-2400 [MEDIUM] CVE-2022-2400: php-dompdf - External Control of File Name or Path in GitHub repository dompdf/dompdf prior t...
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
Scope: local
bookworm: resolved (fixed in 2.0.2+dfsg-1)
bullseye: resolved (fixed in 0.6.2+dfsg-3.1+deb11u1)
sid: resolved (fixed in 2.0.2+dfsg-1)
OSV
php-dompdf vulnerabilities
osv·2023-08-10·CVSS 6.5
CVE-2014-5011 [MEDIUM] php-dompdf vulnerabilities
php-dompdf vulnerabilities
USN-6277-1 fixed vulnerabilities in Dompdf. This update provides the
corresponding updates for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly vali
OSV
php-dompdf vulnerabilities
osv·2023-08-08·CVSS 6.5
CVE-2014-5011 [MEDIUM] php-dompdf vulnerabilities
php-dompdf vulnerabilities
It was discovered that Dompdf was not properly validating untrusted input when
processing HTML content under certain circumstances. An attacker could
possibly use this issue to expose sensitive information or execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2014-5011, CVE-2014-5012, CVE-2014-5013)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced PHAR files, which could result in the deserialization
of untrusted data. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-3838)
It was discovered that Dompdf was not properly validating processed HTML
content that referenced both a remote base and a local file, which could
result in the bypass of a chroot check. An atta
OSV
Dompdf before v2.0.0 vulnerable to chroot check bypass
osv·2022-07-19
CVE-2022-2400 [MEDIUM] Dompdf before v2.0.0 vulnerable to chroot check bypass
Dompdf before v2.0.0 vulnerable to chroot check bypass
Dompdf prior to version 2.0.0 is vulnerable to a chroot check bypass, which could cause disclosure of png and jpeg files.
GHSA
Dompdf before v2.0.0 vulnerable to chroot check bypass
ghsa·2022-07-19
CVE-2022-2400 [MEDIUM] CWE-73 Dompdf before v2.0.0 vulnerable to chroot check bypass
Dompdf before v2.0.0 vulnerable to chroot check bypass
Dompdf prior to version 2.0.0 is vulnerable to a chroot check bypass, which could cause disclosure of png and jpeg files.
OSV
CVE-2022-2400: External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2
osv·2022-07-18·CVSS 5.3
CVE-2022-2400 [MEDIUM] CVE-2022-2400: External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439e7ee0bb6ahttps://huntr.dev/bounties/a6da5e5e-86be-499a-a3c3-2950f749202ahttps://lists.debian.org/debian-lts-announce/2023/07/msg00017.htmlhttps://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439e7ee0bb6ahttps://huntr.dev/bounties/a6da5e5e-86be-499a-a3c3-2950f749202ahttps://lists.debian.org/debian-lts-announce/2023/07/msg00017.html
2022-07-18
Published