CVE-2024-40639

Rejected reason: This CVE is a duplicate of another CVE.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

17 Jul 2024, 20:15

Type Values Removed Values Added
Summary (en) Gotenberg provides a developer-friendly API to interact with powerful tools like Chromium and LibreOffice for converting numerous document formats (HTML, Markdown, Word, Excel, etc.) into PDF files, and more! Prior to version 8.1.0, the default value for the flag `--chromium-deny-list` allowed to display some internal files from the Gotenberg container. Version 8.1.0 provides a new default value fixing the issue. Prior to version 8.1.0, Gotenberg uses the standard `regexp` Go library, which does not support negative lookahead. Therefore, the new default value for the `--chromium-deny-list` is not applicable. However, one could find an alternative using either or both `--chromium-deny-list` and `--chromium-allow-list` flags. Users are advised to upgrade. There are no known workarounds for this vulnerability. (en) Rejected reason: This CVE is a duplicate of another CVE.
References
  • {'url': 'https://github.com/gotenberg/gotenberg/commit/ad152e62e5124b673099a9103eb6e7f933771794', 'source': 'security-advisories@github.com'}
  • {'url': 'https://github.com/gotenberg/gotenberg/security/advisories/GHSA-rh2x-ccvw-q7r3', 'source': 'security-advisories@github.com'}
CWE CWE-200
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : unknown

17 Jul 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-17 18:15

Updated : 2024-07-17 20:15


NVD link : CVE-2024-40639

Mitre link : CVE-2024-40639

CVE.ORG link : CVE-2024-40639


JSON object : View

Products Affected

No product.

CWE

No CWE.