CVE-2020-18972: Medium severity podofo vulnerability
Published Aug 25, 2021
·Updated
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Affected Software
1 affected component
Podofo Project Podofo=0.9.6
Event History
Aug 25, 2021
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18972?
CVE-2020-18972 is considered a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2020-18972?
To fix CVE-2020-18972, upgrade to a patched version of PoDoFo that addresses this vulnerability.
3
What information is exposed in CVE-2020-18972?
CVE-2020-18972 allows attackers to obtain sensitive information through the 'IsNextToken' function.
4
Which version of PoDoFo is affected by CVE-2020-18972?
PoDoFo version 0.9.6 is affected by CVE-2020-18972.
5
Who are the potential attackers for CVE-2020-18972?
Unauthorized actors can exploit CVE-2020-18972 to gain access to sensitive information.