CRITICAL9.8
GHSA-rhwx-hjx2-x4qr
PDFKit vulnerable to Command Injection
Quick fix
GHSA-rhwx-hjx2-x4qr — pdfkit: upgrade to the fixed version with the command below.
bundle update pdfkitDetails
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized.
Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25765[ADVISORY]
- https://github.com/pdfkit/pdfkit/issues/517[WEB]
- https://github.com/pdfkit/pdfkit/pull/519[WEB]
- https://github.com/pdfkit/pdfkit[PACKAGE]
- https://github.com/pdfkit/pdfkit/blob/46cdf53ec540da1a1a2e4da979e3e5fe2f92a257/lib/pdfkit/pdfkit.rb#L55-L58[WEB]
- https://github.com/pdfkit/pdfkit/blob/46cdf53ec540da1a1a2e4da979e3e5fe2f92a257/lib/pdfkit/pdfkit.rb%23L55-L58[WEB]
- https://github.com/pdfkit/pdfkit/blob/master/lib/pdfkit/source.rb%23L44-L50[WEB]
- https://github.com/pdfkit/pdfkit/releases/tag/v0.8.7[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/pdfkit/CVE-2022-25765.yml[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C36GAV3TKM3JXV6UVMLMTTDRCPKSNETQ[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ESWB6SX7HYWQ54UGBGQOZ7G24O6RAOKD[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JFB2BFKH5SUGRKXMY6PWRQNGKZML7GDT[WEB]
- https://security.snyk.io/vuln/SNYK-RUBY-PDFKIT-2869795[WEB]
- http://packetstormsecurity.com/files/171746/pdfkit-0.8.7.2-Command-Injection.html[WEB]