CVE-2020-13452

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:01

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/160744/Gotenberg-6.2.0-Traversal-Code-Execution-Insecure-Permissions.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/160744/Gotenberg-6.2.0-Traversal-Code-Execution-Insecure-Permissions.html - Third Party Advisory, VDB Entry
References () https://github.com/thecodingmachine/gotenberg/issues/199 - Third Party Advisory () https://github.com/thecodingmachine/gotenberg/issues/199 - Third Party Advisory

Information

Published : 2021-01-07 22:15

Updated : 2024-11-21 05:01


NVD link : CVE-2020-13452

Mitre link : CVE-2020-13452

CVE.ORG link : CVE-2020-13452


JSON object : View

Products Affected

thecodingmachine

  • gotenberg
CWE
CWE-276

Incorrect Default Permissions