CVE-2021-3902
CRITICAL9.8EPSS 5.1%Improper Restriction of XML External Entity Reference in dompdf/dompdf
發布日:2024/11/15修改日:2026/4/28
描述
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.
受影響套件(2)
- Debian/php-dompdffrom 0, < 2.0.2+dfsg-1
- Packagist/dompdf/dompdffrom 0, < 2.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-3902
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2021-3902
- PATCHhttps://github.com/dompdf/dompdf
- WEBhttps://github.com/dompdf/dompdf/commit/f56bc8e40be6c0ae0825e6c7396f4db80620b799
- WEBhttps://huntr.com/bounties/a6071c07-806f-429a-8656-a4742e4191b1