HIGH
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI
Published Nov 5, 2019
7.5
HIGHCVSS 3.1
EPSS 3.42%
Description
PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5707 Advisory
- https://github.com/advisories/GHSA-x43g-gj9x-838x Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-17221
- https://web.archive.org/web/20191220171022/https://www.darkmatter.ae/blogs/breaching-the-perimeter-phantomjs-arbitrary-file-read/
- https://www.darkmatter.ae/blogs/breaching-the-perimeter-phantomjs-arbitrary-file-read/ x_refsource_MISCExploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 5, 2019
Updated Aug 5, 2024
Reserved Oct 6, 2019
Link CVE-2019-17221
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-X43G-GJ9X-838X