GHSA-rhwx-hjx2-x4qr
Dashboard / Vulnerabilities / GHSA-rhwx-hjx2-x4qr
Summary: PDFKit vulnerable to Command Injection
Details: The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-25765, https://github.com/pdfkit/pdfkit/issues/517, https://github.com/pdfkit/pdfkit/pull/519, https://github.com/pdfkit/pdfkit, https://github.com/pdfkit/pdfkit/blob/46cdf53ec540da1a1a2e4da979e3e5fe2f92a257/lib/pdfkit/pdfkit.rb#L55-L58, https://github.com/pdfkit/pdfkit/blob/46cdf53ec540da1a1a2e4da979e3e5fe2f92a257/lib/pdfkit/pdfkit.rb%23L55-L58, https://github.com/pdfkit/pdfkit/blob/master/lib/pdfkit/source.rb%23L44-L50, https://github.com/pdfkit/pdfkit/releases/tag/v0.8.7, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/pdfkit/CVE-2022-25765.yml, https://lists.fedoraproject.org/archives/list/[email protected]/message/C36GAV3TKM3JXV6UVMLMTTDRCPKSNETQ, https://lists.fedoraproject.org/archives/list/[email protected]/message/ESWB6SX7HYWQ54UGBGQOZ7G24O6RAOKD, https://lists.fedoraproject.org/archives/list/[email protected]/message/JFB2BFKH5SUGRKXMY6PWRQNGKZML7GDT, https://security.snyk.io/vuln/SNYK-RUBY-PDFKIT-2869795, http://packetstormsecurity.com/files/171746/pdfkit-0.8.7.2-Command-Injection.html
Affected packages
Package
Name: pdfkit
Purl: pkg:gem/pdfkit
Affected ranges
Type: ECOSYSTEM
Events:
