2024-12-08 03:06:42 +00:00

96 lines
3.7 KiB
JSON

{
"id": "CVE-2024-37169",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-06-10T22:15:12.663",
"lastModified": "2024-11-21T09:23:21.103",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Playright's screenshot feature to exploit the file wrapper. Version 2.0.3 mitigates this issue by requiring input URLs to be of protocol `http` or `https`. No known workarounds are available aside from upgrading."
},
{
"lang": "es",
"value": "@jmondi/url-to-png es una utilidad de URL a PNG autohospedada. Las versiones anteriores a la 2.0.3 son vulnerables a la lectura arbitraria de archivos si un actor de amenazas utiliza la funci\u00f3n de captura de pantalla de Playright para explotar el contenedor del archivo. La versi\u00f3n 2.0.3 mitiga este problema al requerir que las URL de entrada sean del protocolo \"http\" o \"https\". No hay workarounds disponibles aparte de la actualizaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"references": [
{
"url": "https://github.com/jasonraimondi/url-to-png/commit/9336020c5e603323f5cf4a2ac3bb9a7735cf61f7",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/issues/47",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/releases/tag/v2.0.3",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/security/advisories/GHSA-665w-mwrr-77q3",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/user-attachments/files/15536336/Arbitrary.File.Read.via.Playwright.s.Screenshot.Feature.Exploiting.File.Wrapper.pdf",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/commit/9336020c5e603323f5cf4a2ac3bb9a7735cf61f7",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/issues/47",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/releases/tag/v2.0.3",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jasonraimondi/url-to-png/security/advisories/GHSA-665w-mwrr-77q3",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/user-attachments/files/15536336/Arbitrary.File.Read.via.Playwright.s.Screenshot.Feature.Exploiting.File.Wrapper.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}