Files
CVEs-PoC/2020/CVE-2020-13452.md
T
2024-05-25 21:48:12 +02:00

18 lines
735 B
Markdown

### [CVE-2020-13452](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13452)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
### POC
#### Reference
- http://packetstormsecurity.com/files/160744/Gotenberg-6.2.0-Traversal-Code-Execution-Insecure-Permissions.html
#### Github
- https://github.com/br0xpl/gotenberg_hack