CVE-2021-3838
php-dompdf - security update
9.8
CRITICAL
CVSS 3.1
EPSS 1.4%
描述
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.
如何修補 CVE-2021-3838
要修補 CVE-2021-3838,請將受影響套件升級到下列已修補版本。
- —升級至 0.6.2+dfsg-3.1+deb11u1 或更新版本
- —升級至 0.6.2+dfsg-3+deb10u1 或更新版本
- —升級至 0.6.2+dfsg-3+deb10u2 或更新版本
- —升級至 0.6.2+dfsg-3.1+deb11u1 或更新版本
- —升級至 2.0.0 或更新版本
CVE-2021-3838 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 0.6.2+dfsg-3.1+deb11u1
- from 0, < 0.6.2+dfsg-3+deb10u1
- from 0, < 0.6.2+dfsg-3+deb10u2
- from 0, < 0.6.2+dfsg-3.1+deb11u1
- from 0, < 2.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |