First published: Fri Nov 15 2024(Updated: )
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dompdf/dompdf | <2.0.0 | 2.0.0 |
Dompdf | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3902 has a medium severity rating due to its potential for exploitation through SSRF and deserialization attacks.
To fix CVE-2021-3902, upgrade to dompdf version 2.0.0 or higher.
CVE-2021-3902 affects all versions of dompdf prior to 2.0.0.
Yes, CVE-2021-3902 can be exploited regardless of whether the isRemoteEnabled option is set to true or false.
CVE-2021-3902 can facilitate Server-Side Request Forgery (SSRF) and deserialization attacks.