CVE-2024-28184
09.03.2024, 01:15
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.Enginsight
| Vendor | Product | Version |
|---|---|---|
| kozea | weasyprint | 61.0 ≤ 𝑥 < 61.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References