CVE-2020-13451

CRITICAL

Gotenberg <6.2.1 - Code Injection

Title source: llm
STIX 2.1

Description

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.

Scores

CVSS v3 9.8
EPSS 0.0058
EPSS Percentile 68.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-459
Status published
Products (1)
thecodingmachine/gotenberg < 6.2.1
Published Jan 07, 2021
Tracked Since Feb 18, 2026