Dompdf prior to version 2.0.0 is vulnerable to a chroot check bypass, which could cause disclosure of png and jpeg files.

Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.

https://github.com/dompdf/dompdf/releases/tag/v2.0.0

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

realityloop created an issue. See original summary.

realityloop’s picture

Status: Active » Needs review

gaurav.kapoor’s picture

Status: Needs review » Fixed

Merged. Thanks for working on this.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.