CVE-2021-3838

EUVD-2024-3197
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
@huntr_aiCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
dompdf_projectdompdf
𝑥
< 2.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-dompdf
bookworm
2.0.3+dfsg-1
fixed
bullseye
no-dsa
sid
3.0.0+dfsg-2
fixed
trixie
3.0.0+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php-dompdf
bionic
Fixed 0.6.2+dfsg-3ubuntu0.18.04.1~esm1
released
focal
Fixed 0.6.2+dfsg-3ubuntu0.20.04.1
released
jammy
Fixed 0.6.2+dfsg-3.1ubuntu0.1
released
kinetic
ignored
lunar
dne
trusty
ignored
xenial
Fixed 0.6.1+dfsg-2ubuntu1+esm1
released