CVE-2024-33864: SSRF
An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33864?
CVE-2024-33864 has been identified as a critical vulnerability due to its exploitation potential leading to SSRF attacks.
How do I fix CVE-2024-33864?
To mitigate CVE-2024-33864, upgrade linqi to version 1.4.0.1 or later, which addresses the SSRF vulnerabilities.
What types of attacks are facilitated by CVE-2024-33864?
CVE-2024-33864 facilitates SSRF attacks via document template generation that can exploit remote images, file inclusion, and PDF generation.
Which versions of linqi are affected by CVE-2024-33864?
CVE-2024-33864 affects all versions of linqi prior to 1.4.0.1.
Is there a workaround for CVE-2024-33864 if I cannot update immediately?
Currently, there are no known effective workarounds for CVE-2024-33864; updating to the latest version is strongly recommended.