CVE-2021-42560
12.01.2022, 19:15
An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).Enginsight
| Vendor | Product | Version |
|---|---|---|
| mitre | caldera | 2.9.0 |
𝑥
= Vulnerable software versions
References