CVE-2019-20836: Infoleak
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstrated by Google Drive.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.5
Foxitsoftware Reader<9.5
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Foxit Reader and PhantomPDF?
The vulnerability ID for this issue in Foxit Reader and PhantomPDF is CVE-2019-20836.
2
What is the severity of CVE-2019-20836?
The severity of CVE-2019-20836 is high with a severity value of 7.5.
3
What is the affected software by CVE-2019-20836?
The affected software by CVE-2019-20836 is Foxit Reader and PhantomPDF versions up to 9.5.
4
What is the description of CVE-2019-20836?
CVE-2019-20836 is a vulnerability in Foxit Reader and PhantomPDF before 9.5 that involves mishandling of cloud credentials, specifically in relation to Google Drive.
5
How can I fix CVE-2019-20836?
To fix CVE-2019-20836, it is recommended to update Foxit Reader and PhantomPDF to version 9.5 or higher, as this issue has been addressed in that version.