DRUPAL-CONTRIB-2022-048

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2022-048

    DRUPAL-CONTRIB-2022-048

    Published: 13 Jul 2022Last Modified: 10 Sept 2026

    Summary:

    Details: This module enables you to generate print versions of content. Some installations of the module make use of the dompdf/dompdf third-party dependency. Security vulnerabilities exist for versions of dompdf/dompdf < 2.0.0 See the library release notes for more detail: <https://github.com/dompdf/dompdf/releases/tag/v2.0.0> ### Note on 3rd party vulnerabilities This security advisory corresponds to a 3rd party vulnerability. Normally the Drupal Security Team would not issue advisories related to 3rd party code that is shipped separately from a module per our policy (most recent update is [PSA-2019-09-04](https://www.drupal.org/psa-2019-09-04)). In this case, because the module required a specific version and could not be updated without a change to the Drupal module we do issue an advisory.

    Affected packages

    Package

    Name: drupal/entity_print

    Purl: pkg:composer/drupal/entity_print?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.6.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CONTRIB-2022-048 | CVE-DB