CVE-2020-13452
—CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
- Vendors
- thecodingmachine
- Products
- gotenberg
- Weakness
- CWE-276
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.