ZeroHour

CVE-2020-13452

CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

Vendors
thecodingmachine
Products
gotenberg
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.