CVE-2024-28184

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-28184
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-28184.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-28184
Aliases
Related
Published
2024-03-09T01:15:07Z
Modified
2024-10-12T11:21:10.836315Z
Summary
[none]
Details

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.

References

Affected packages

Debian:13 / weasyprint

Package

Name
weasyprint
Purl
pkg:deb/debian/weasyprint?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
61.2-1

Affected versions

57.*

57.2-1

59.*

59.0-1

60.*

60.2-1

61.*

61.0-1
61.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/kozea/weasyprint

Affected ranges

Type
GIT
Repo
https://github.com/kozea/weasyprint
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1
v0.10
v0.11
v0.12
v0.13
v0.14
v0.15
v0.16
v0.17
v0.17.1
v0.18
v0.19
v0.19.1
v0.19.2
v0.2
v0.20
v0.20.1
v0.20.2
v0.21
v0.22
v0.23
v0.24
v0.25
v0.26
v0.27
v0.28
v0.29
v0.30
v0.31
v0.32
v0.33
v0.34
v0.35
v0.36
v0.37
v0.38
v0.39
v0.4
v0.40
v0.41
v0.42
v0.5
v0.6
v0.7
v0.8
v0.9

Other

v43
v43rc1
v43rc2
v44
v45
v46
v47
v48
v49
v50
v51
v52

v52.*

v52.1
v52.2

v53.*

v53.0
v53.0b1
v53.0b2
v53.1
v53.2
v53.3
v53.4

v54.*

v54.0
v54.0b1
v54.1
v54.2
v54.3

v55.*

v55.0
v55.0b1

v56.*

v56.0
v56.0b1
v56.1

v57.*

v57.0
v57.0b1
v57.1
v57.2

v58.*

v58.0
v58.0b1
v58.1

v59.*

v59.0
v59.0b1

v60.*

v60.0
v60.1
v60.2

v61.*

v61.0
v61.1