CVE-2023-33733: Code Injection
Reportlab up to and including v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
Other sources
Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/reportlabto a version that resolves this vulnerability.Fixed in 3.6.13
Event History
Frequently Asked Questions
What is CVE-2023-33733?
CVE-2023-33733 is a vulnerability in Reportlab up to and including v3.6.12 that allows attackers to execute arbitrary code through a manipulated PDF file.
What is the severity of CVE-2023-33733?
The severity of CVE-2023-33733 is high with a score of 7.8.
How does CVE-2023-33733 affect Reportlab?
CVE-2023-33733 affects Reportlab up to and including v3.6.12.
How can attackers exploit CVE-2023-33733?
Attackers can exploit CVE-2023-33733 by providing a crafted PDF file.
How can I mitigate the CVE-2023-33733 vulnerability?
To mitigate the CVE-2023-33733 vulnerability, update Reportlab to version 3.6.13 or later.