Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS04YzJjLWp4d2otanFnZs4AAwCy
Browsershot does not validate URL protocols passed to Browsershot URL method
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
Permalink: https://github.com/advisories/GHSA-8c2c-jxwj-jqgfJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04YzJjLWp4d2otanFnZs4AAwCy
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 year ago
Updated: 8 months ago
CVSS Score: 8.2
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Identifiers: GHSA-8c2c-jxwj-jqgf, CVE-2022-41706
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-41706
- https://fluidattacks.com/advisories/eminem/
- https://github.com/spatie/browsershot/commit/92cf16fc098211731f80d21687abeafbe2c457ad
- https://github.com/advisories/GHSA-8c2c-jxwj-jqgf
Affected Packages
packagist:spatie/browsershot
Versions: < 3.57.3Fixed in: 3.57.3