CVE-2024-28184
published 2024-03-09CVE-2024-28184: WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs…
PriorityP346high7.4CVSS 3.1
AVNACLPRLUINSCCLILAL
EPSS
0.62%
46.4th percentile
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | weasyprint | < weasyprint 61.2-1 (forky) | weasyprint 61.2-1 (forky) |
| fedoraproject | fedora | — | — |
| kozea | weasyprint | — | — |
| kozea | weasyprint | >= 0 < 61.2-1 | 61.2-1 |
| kozea | weasyprint | >= 0 < 61.2-1 | 61.2-1 |
| kozea | weasyprint | >= 61.0 < 61.2 | 61.2 |
| kozea | weasyprint | >= 61.0 < 61.2 | 61.2 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
osv7.4HIGH
vendor_debian7.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-28184: weasyprint - WeasyPrint helps web developers to create PDF documents. Since version 61.0, the...
vendor_debian·2024·CVSS 7.4
CVE-2024-28184 [HIGH] CVE-2024-28184: weasyprint - WeasyPrint helps web developers to create PDF documents. Since version 61.0, the...
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 61.2-1)
sid: resolved (fixed in 61.2-1)
trixie: resolved (fixed in 61.2-1)
OSV
CVE-2024-28184: WeasyPrint helps web developers to create PDF documents
osv·2024-03-09·CVSS 7.4
CVE-2024-28184 [HIGH] CVE-2024-28184: WeasyPrint helps web developers to create PDF documents
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
OSV
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
osv·2024-03-08
CVE-2024-28184 [HIGH] WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
### Impact
Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs.
### Patches
Fixed by 734ee8e that’s included in 61.2
### Workarounds
- Check that no PDF attachment is defined in source HTML.
- Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.
GHSA
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
ghsa·2024-03-08
CVE-2024-28184 [HIGH] CWE-829 WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
### Impact
Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs.
### Patches
Fixed by 734ee8e that’s included in 61.2
### Workarounds
- Check that no PDF attachment is defined in source HTML.
- Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Kozea/WeasyPrint/commit/734ee8e2dc84ff3090682f3abff056d0907c8598https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-35jj-wx47-4w8rhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ZLQZMOEDY72TS43HDXOBVID2VYCTWIH6/https://github.com/Kozea/WeasyPrint/commit/734ee8e2dc84ff3090682f3abff056d0907c8598https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-35jj-wx47-4w8rhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ZLQZMOEDY72TS43HDXOBVID2VYCTWIH6/
2024-03-09
Published