Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-27586
HistoryMar 20, 2023 - 4:15 p.m.

CVE-2023-27586

2023-03-2016:15:13
Alpine Linux Development Team
security.alpinelinux.org
21
cairosvg
2d graphics library
security vulnerability
svg converter
server-side request forgery
denial of service
version 2.7.0

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

38.6%

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to version 2.7.0, Cairo can send requests to external hosts when processing SVG files. A malicious actor could send a specially crafted SVG file that allows them to perform a server-side request forgery or denial of service. Version 2.7.0 disables CairoSVG’s ability to access other files online by default.

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

38.6%