Known Vulnerabilities for Rendertron by Google
Listed below are 5 of the newest known vulnerabilities associated with "Rendertron" by "Google".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-8902 json | Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a ... | 4.3 - MEDIUM | 2021-02-23 | 2023-11-07 |
| CVE-2017-18355 json | Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the s... | 7.5 - HIGH | 2018-12-17 | 2019-02-07 |
| CVE-2017-18354 json | Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitr... | 7.5 - HIGH | 2018-12-17 | 2019-01-04 |
| CVE-2017-18353 json | Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all us... | 7.5 - HIGH | 2018-12-17 | 2019-10-03 |
| CVE-2017-18352 json | Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. | 6.1 - MEDIUM | 2018-12-17 | 2019-01-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rendertron | 3.1.0 | ||||
| Application | Rendertron | 3.0.0 | ||||
| Application | Rendertron | 2.0.0 | ||||
| Application | Rendertron | 1.1.1 | ||||
| Application | Rendertron | 1.1.0 | ||||
| Application | Rendertron | 1.0.0 | ||||
| Application | Rendertron | - |