PT-2021-9614 · Gotenberg · Gotenberg

Published

2021-01-07

·

Updated

2021-01-08

·

CVE-2020-13452

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gotenberg versions 6.2.1 and earlier
Description The issue is related to insecure permissions for tini, which is writable by the gotenberg user. This potentially allows an attacker to overwrite the file, leading to denial of service or code execution.
Recommendations For Gotenberg versions 6.2.1 and earlier, update to a version where the permissions for tini are properly secured to prevent overwrite attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13452

Affected Products

Gotenberg