Google Rendertron vulnerabilities

5 known vulnerabilities affecting google/rendertron.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-8902MEDIUMCVSS 4.3fixed in 3.0.02021-02-23
CVE-2020-8902 [LOW] CWE-284 CVE-2020-8902: Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attac Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you ca
nvd
CVE-2017-18353HIGHCVSS 7.5v1.0.02018-12-17
CVE-2017-18353 [HIGH] CVE-2017-18353: Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
nvd
CVE-2017-18355HIGHCVSS 7.5v1.0.02018-12-17
CVE-2017-18355 [HIGH] CWE-200 CVE-2017-18355: Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to rea Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
nvd
CVE-2017-18354HIGHCVSS 7.5v1.0.02018-12-17
CVE-2017-18354 [HIGH] CWE-22 CVE-2017-18354: Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusi Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
nvd
CVE-2017-18352MEDIUMCVSS 6.1v1.0.02018-12-17
CVE-2017-18352 [MEDIUM] CWE-79 CVE-2017-18352: Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URL Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
nvd
Google Rendertron vulnerabilities | cvebase