CVE-2022-35583
9.8
CRITICAL
CVSS 3.1
EPSS 11.3%
Description
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
How to fix CVE-2022-35583
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/wkhtmltopdf—no fix listed
Is CVE-2022-35583 being exploited?
Moderate — EPSS is 11.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |