PT-2024-22317 · Unknown · Weasyprint

Nullie

·

Published

2024-03-08

·

Updated

2024-03-23

·

CVE-2024-28184

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WeasyPrint versions 61.0 through 61.1
Description WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url fetcher is configured to prevent access to files and URLs.
Recommendations For WeasyPrint versions 61.0 through 61.1, update to version 61.2 to resolve the issue. As a temporary workaround, check that no PDF attachment is defined in source HTML. Launch WeasyPrint in a sandbox that prevents access to the filesystem and the network.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-28184
GHSA-35JJ-WX47-4W8R

Affected Products

Weasyprint