tt9133github / libraryiotest

libraryiotest
0 stars 0 forks source link

CVE-2019-1000005 (High) detected in mpdf/mpdf-v7.1.6 - autoclosed #200

Closed mend-bolt-for-github[bot] closed 2 years ago

mend-bolt-for-github[bot] commented 3 years ago

CVE-2019-1000005 - High Severity Vulnerability

Vulnerable Library - mpdf/mpdf-v7.1.6

A PHP class to generate PDF files from HTML with Unicode/UTF-8 and CJK support

Library home page: https://api.github.com/repos/mpdf/mpdf/zipball/ef5d8cf2c63def40fb76fc0a9e286721cb4dffcd

Dependency Hierarchy: - :x: **mpdf/mpdf-v7.1.6** (Vulnerable Library)

Found in HEAD commit: b5de81a90a4d1c556b0e6849ad9289f921a18697

Vulnerability Details

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content . This vulnerability appears to have been fixed in 7.1.8.

Publish Date: 2019-02-04

URL: CVE-2019-1000005

CVSS 3 Score Details (8.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1000005

Release Date: 2019-02-04

Fix Resolution: v7.1.8


Step up your Open Source Security Game with WhiteSource here

mend-bolt-for-github[bot] commented 2 years ago

:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.