CVE-2020-7790: Arbitrary File Read
Published Dec 11, 2020
·Updated
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
Affected Software
2 affected componentsFixes available
spatie browsershot
composer/spatie/browsershot<3.40.1
3.40.1
Event History
Dec 11, 2020
CVE Published
via MITRE·10:50 AM
Data Sourced
via MITRE·10:50 AM
DescriptionSeverityWeakness
May 24, 2022
Advisory Published
via GitHub·05:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-7790?
CVE-2020-7790 is considered a high severity vulnerability due to its potential for arbitrary file inclusion.
2
How do I fix CVE-2020-7790?
To fix CVE-2020-7790, upgrade the spatie/browsershot package to version 3.40.1 or later.
3
What is affected by CVE-2020-7790?
CVE-2020-7790 affects versions of the spatie/browsershot package prior to 3.40.1.
4
What type of attack does CVE-2020-7790 enable?
CVE-2020-7790 enables attackers to include arbitrary files in the resultant PDF by using the file:// protocol.
5
Is the spatie/browsershot package safe to use?
The spatie/browsershot package can be safe to use if updated to the fixed version 3.40.1 or beyond.