First published: Fri Sep 09 2022(Updated: )
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
rubygems/pdfkit | <0.8.7.2 | 0.8.7.2 |
Pdfkit | >=0.0.0 | |
Fedora | =35 | |
Fedora | =36 | |
Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25765 is classified as a high-severity vulnerability due to its potential for command injection.
To fix CVE-2022-25765, update the pdfkit package to version 0.8.7.2 or later.
CVE-2022-25765 enables command injection attacks through unsanitized URL inputs.
CVE-2022-25765 affects all versions of pdfkit prior to version 0.8.7.2.
The patch for CVE-2022-25765 is primarily available in pdfkit version 0.8.7.2; ensure that your specific distribution uses this version or later.