CVE-2024-56521: Critical severity tcpdf vulnerability
Published Dec 27, 2024
·Updated
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPTSSLVERIFYHOST and CURLOPTSSLVERIFYPEER are set unsafely.
Affected Software
2 affected componentsFixes available
composer/tecnickcom/tcpdf<6.8.0
6.8.0
Tcpdf Project Tcpdf<6.8.0
Remediation
Patch Available
Event History
Dec 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-56521?
CVE-2024-56521 does not have a publicly assigned CVSS score but is considered a serious security vulnerability in TCPDF.
2
How do I fix CVE-2024-56521?
To fix CVE-2024-56521, you should upgrade TCPDF to version 6.8.0 or later.
3
What are the potential risks of CVE-2024-56521?
The risks of CVE-2024-56521 include insecure SSL verification, which may expose applications to man-in-the-middle attacks.
4
Which versions of TCPDF are affected by CVE-2024-56521?
CVE-2024-56521 affects all versions of TCPDF prior to 6.8.0.
5
Is libcurl needed to be affected by CVE-2024-56521?
Yes, the use of libcurl with TCPDF and improper configuration of SSL verification is necessary for CVE-2024-56521 to be exploitable.