loftwah / shop.grindmodecypher.com

This is the repository for shop.grindmodecypher.com. A website I have built, and maintain for the music group I am in called Grind Mode Cypher.
https://shop.grindmodecypher.com
GNU General Public License v3.0
2 stars 0 forks source link

CVE-2022-41343 (High) detected in dompdf/dompdf-v2.0.0 #55

Open mend-bolt-for-github[bot] opened 1 year ago

mend-bolt-for-github[bot] commented 1 year ago

CVE-2022-41343 - High Severity Vulnerability

Vulnerable Library - dompdf/dompdf-v2.0.0

DOMPDF is a CSS 2.1 compliant HTML to PDF converter

Library home page: https://api.github.com/repos/dompdf/dompdf/zipball/79573d8b8a141ec8a17312515de8740eed014fa9

Dependency Hierarchy: - :x: **dompdf/dompdf-v2.0.0** (Vulnerable Library)

Found in base branch: master

Vulnerability Details

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

Publish Date: 2022-09-25

URL: CVE-2022-41343

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: None - Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-09-25

Fix Resolution: v2.0.1


Step up your Open Source Security Game with Mend here