Vulnerabilities > CVE-2021-23345 - Server-Side Request Forgery (SSRF) vulnerability in Thecodingmachine Gotenberg
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as <iframe src='file:///etc/passwd'>.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |