GHSA-c9f5-29f6-c35w

Suggest an improvement
Source
https://github.com/advisories/GHSA-c9f5-29f6-c35w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-c9f5-29f6-c35w/GHSA-c9f5-29f6-c35w.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-c9f5-29f6-c35w
Aliases
Published
2024-12-20T06:30:45Z
Modified
2025-02-04T17:31:22.538901Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
  • 6.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:P CVSS Calculator
Summary
Browsershot Improper Input Validation vulnerability
Details

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.

Note:

This is a bypass of the fix for CVE-2024-21544.

Database specific
{
    "severity": "MODERATE",
    "nvd_published_at": "2024-12-20T05:15:06Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-125",
        "CWE-20",
        "CWE-200"
    ],
    "github_reviewed_at": "2024-12-20T15:08:54Z"
}
References

Affected packages

Packagist / spatie/browsershot

Package

Name
spatie/browsershot
Purl
pkg:composer/spatie/browsershot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.3

Affected versions

0.*

0.1.0
0.1.1
0.1.2
0.1.3

1.*

1.0.0
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0
1.7.0
1.8.0
1.9.0
1.9.1

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2

3.*

3.0.0
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.4.0
3.5.0
3.6.0
3.7.0
3.8.0
3.8.1
3.9.0
3.10.0
3.11.0
3.11.1
3.12.0
3.13.0
3.14.0
3.14.1
3.15.0
3.16.0
3.16.1
3.17.0
3.18.0
3.19.0
3.20.0
3.20.1
3.22.0
3.22.1
3.23.0
3.23.1
3.24.0
3.25.0
3.25.1
3.26.0
3.26.1
3.26.2
3.26.3
3.27.0
3.29.0
3.30.0
3.31.0
3.31.1
3.32.0
3.32.1
3.32.2
3.33.0
3.33.1
3.34.0
3.35.0
3.36.0
3.37.0
3.37.1
3.37.2
3.38.0
3.39.0
3.40.0
3.40.1
3.40.2
3.40.3
3.41.0
3.41.1
3.41.2
3.42.0
3.44.0
3.44.1
3.45.0
3.46.0
3.47.0
3.48.0
3.49.0
3.50.0
3.50.1
3.50.2
3.51.0
3.52.0
3.52.1
3.52.2
3.52.3
3.52.4
3.52.5
3.52.6
3.53.0
3.54.0
3.55.0
3.56.0
3.57.0
3.57.1
3.57.2
3.57.3
3.57.4
3.57.5
3.57.6
3.57.7
3.57.8
3.58.0
3.58.1
3.58.2
3.59.0
3.60.0
3.60.1
3.60.2
3.61.0

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.2.1
4.3.0
4.3.1
4.4.0

5.*

5.0.0
5.0.1
5.0.2