CVE-2023-42361

Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:midori-global:better_pdf_exporter:*:*:*:*:*:jira_data_center:*:*
cpe:2.3:a:midori-global:better_pdf_exporter:*:*:*:*:*:jira_server:*:*

History

21 Nov 2024, 08:22

Type Values Removed Values Added
References () https://gccybermonks.com/posts/pdfjira/ - Third Party Advisory () https://gccybermonks.com/posts/pdfjira/ - Third Party Advisory
References () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=datacenter - Product () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=datacenter - Product
References () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=server - Product () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=server - Product

15 Nov 2023, 15:36

Type Values Removed Values Added
CWE CWE-918
CPE cpe:2.3:a:midori-global:better_pdf_exporter:*:*:*:*:*:jira_data_center:*:*
cpe:2.3:a:midori-global:better_pdf_exporter:*:*:*:*:*:jira_server:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Midori-global
Midori-global better Pdf Exporter
References () https://gccybermonks.com/posts/pdfjira/ - () https://gccybermonks.com/posts/pdfjira/ - Third Party Advisory
References () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=datacenter - () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=datacenter - Product
References () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=server - () https://marketplace.atlassian.com/apps/5167/better-pdf-exporter-for-jira?tab=versions&hosting=server - Product

07 Nov 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-07 22:15

Updated : 2024-11-21 08:22


NVD link : CVE-2023-42361

Mitre link : CVE-2023-42361

CVE.ORG link : CVE-2023-42361


JSON object : View

Products Affected

midori-global

  • better_pdf_exporter
CWE
CWE-918

Server-Side Request Forgery (SSRF)