CVE-2024-21547

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 18, 2024
CWE ID 22

Summary

CVE-2024-21547 is a newly disclosed vulnerability affecting versions of the package spatie/browsershot prior to 5.0.2. This issue stems from URI normalization in the browser component, where file:// checks can be circumvented using file:\\\. An attacker can leverage this weakness to traverse directories and read any file on the server. This poses a significant risk as sensitive data may be accessed without proper authorization. It is recommended that users upgrade to the latest version of spatie/browsershot to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share