OSV 1.4.0 · github-reviewed · 修改于 2021-04-22 04:52
发布时间
2021-05-11 02:38
GitHub 审查时间
2021-04-22 04:52
NVD 发布时间
2020-10-07 02:15
源文件
advisories/github-reviewed/2021/05/GHSA-hcq6-h8v2-r5wm/GHSA-hcq6-h8v2-r5wm.json
This affects all versions of package node-pdf-generator up to and including 0.0.6. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.