-
-
Notifications
You must be signed in to change notification settings - Fork 980
Closed
Description
Describe the bug
Dompdf 2.0.0 Released and support is needed, it addresses multiple security vulnerabilities
Additional context
https://github.com/dompdf/dompdf/releases/tag/v2.0.0
The release addresses the following announced vulnerabilities:
| Vulnerability | References | Type | Severity |
|---|---|---|---|
| Improper Restriction of XML External Entity Reference | #2564 | Information Disclosure | TBD |
| Deserialization of Untrusted Data | #2564 | Remote Code Execution | Critical |
| External Control of File Name or Path | #2564 | Information Disclosure | TBD |
| Server-Side Request Forgery | #2564 | Information Disclosure | TBD |
PaolaRuby and padre
Metadata
Metadata
Assignees
Labels
No labels