Insecure Permissions in Gotenberg's Tini File: Potential Denial of Service and Code Execution Vulnerability

Insecure Permissions in Gotenberg's Tini File: Potential Denial of Service and Code Execution Vulnerability

CVE-2020-13452 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

Learn more about our User Device Pen Test.