PT-2022-16401 · Dompdf+3 · Dompdf+3

Published

2022-07-18

·

Updated

2025-12-30

·

CVE-2022-2400

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions dompdf versions prior to 2.0.0
Description The issue concerns a chroot check bypass that could lead to the disclosure of png and jpeg files. It allows for external control of file name or path in the GitHub repository dompdf/dompdf.
Recommendations For versions prior to 2.0.0, update to version 2.0.0 or later to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-2400
DLA-3495-1
DLA-3495-2
DLA-4427-1
GHSA-5QJ8-6XXJ-HP9H
USN-6277-1
USN-6277-2

Affected Products

Debian
Linuxmint
Ubuntu
Dompdf