MEDIUM6.1
GHSA-6q49-35h6-rq2p
Browsershot version 3.57.3 vulnerable to improper input validation
Quick fix
GHSA-6q49-35h6-rq2p — spatie/browsershot: upgrade to the fixed version with the command below.
composer require spatie/browsershot:^3.57.4Details
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/spatie/browsershot
Introduced in:
0Fixed in: 3.57.4Fix
composer require spatie/browsershot:^3.57.4References
- https://nvd.nist.gov/vuln/detail/CVE-2022-43984[ADVISORY]
- https://github.com/spatie/browsershot/commit/554c3e566fde8c47ad1ac9be47eaeb9a84c4dfe2[WEB]
- https://github.com/spatie/browsershot/commit/92cf16fc098211731f80d21687abeafbe2c457ad[WEB]
- https://fluidattacks.com/advisories/malone[WEB]
- https://github.com/spatie/browsershot[WEB]