Vulnerabilities > CVE-2020-14160 - Server-Side Request Forgery (SSRF) vulnerability in Thecodingmachine Gotenberg

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
thecodingmachine
CWE-918

Summary

An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.

Common Weakness Enumeration (CWE)