CVE-2023-27586
Summary
| CVE | CVE-2023-27586 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-20 16:15:00 UTC |
| Updated | 2023-03-23 18:23:00 UTC |
| Description | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG's ability to access other files online by default. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| SSRF & DOS vulnerability · Advisory · Kozea/CairoSVG · GitHub |
MISC |
github.com |
|
| Don’t allow fetching external files unless explicitly asked for · Kozea/CairoSVG@12d31c6 · GitHub |
MISC |
github.com |
|
| Version 2.7.0 · Kozea/CairoSVG@33007d4 · GitHub |
MISC |
github.com |
|
| Release 2.7.0 · Kozea/CairoSVG · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181701 Debian Security Update for cairosvg (DSA 5382-1)
- 183240 Debian Security Update for cairosvg (CVE-2023-27586)
- 283811 Fedora Security Update for python (FEDORA-2023-ab86bdbce6)
- 283836 Fedora Security Update for python (FEDORA-2023-064525b17b)
- 284235 Fedora Security Update for python (FEDORA-2023-e4a4ea43d8)
- 503222 Alpine Linux Security Update for py3-cairosvg
- 506171 Alpine Linux Security Update for py3-cairosvg