CVE-2020-13452

CRITICAL

Gotenberg < 6.2.1 - Insecure Permissions Leading to Denial of Service or Code Execution

Title source: llm
STIX 2.1

Description

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0275
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
thecodingmachine/gotenberg < 6.2.1
Published Jan 07, 2021
Tracked Since Feb 18, 2026