CVE-2021-42560

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
6.5
MEDIUM
Affected
2
PROJECTS

Description

An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery, Out of Band Exfiltration, etc.).

Automated Adversary Emulation Platform
GitHubGitHub
7.02K
Public Disclosures
GitHubGitHub
92