In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
References
Link | Resource |
---|---|
https://github.com/thecodingmachine/gotenberg/issues/199 | Third Party Advisory |
http://packetstormsecurity.com/files/160744/Gotenberg-6.2.0-Traversal-Code-Execution-Insecure-Permissions.html | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2021-01-07 14:15
Updated : 2021-01-08 11:02
NVD link : CVE-2020-13452
Mitre link : CVE-2020-13452
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
thecodingmachine
- gotenberg