Insecure Permissions in Gotenberg's Tini File: Potential Denial of Service and Code Execution Vulnerability
CVE-2020-13452 · CRITICAL Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
Learn more about our User Device Pen Test.