Server-side Request Forgery (SSRF)
Published Feb 18, 2021
7.1
HIGHCVSS 4.0
EPSS 1.33%
Description
All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of reportlab 2. Go to demos -> odyssey -> dodyssey 3. In the text file odyssey.txt that needs to be converted to pdf inject <img src="http://127.0.0.1:5000" valign="top"/> 4. Create a nc listener nc -lp 5000 5. Run python3 dodyssey.py 6. You will get a hit on your nc showing we have successfully proceded to send a server side request 7. dodyssey.py will show error since there is no img file on the url, but we are able to do SSRF
Affected products
- Vendor n/a Product Reportlab Defaultn/a
- Version 0StatusaffectedConstraints<unspecified
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Reportlab | n/a |
|
Configuration 2
- 34
- 35
No data.
Red Hat Enterprise Linux 6
python-reportlab
Out of support scope
Red Hat Enterprise Linux 7
python-reportlab
Out of support scope
Red Hat Enterprise Linux 8
python-reportlab
Will not fix
Red Hat Quay 3
quay/quay-rhel8
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | python-reportlab | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python-reportlab | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | python-reportlab | Will not fix | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is out of support scope for the following products: * Red Hat Enterprise Linux 6 * Red Hat Enterprise Linux 7 To learn more about Red Hat Enterprise Linux support scope, please see https://access.redhat.com/support/policy/updates/errata/
References (16)
- https://access.redhat.com/security/cve/CVE-2020-28463 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1930416 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1930417
- https://github.com/advisories/GHSA-mpvw-25mg-59vx Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/reportlab/PYSEC-2021-146.yaml
- https://hg.reportlab.com/hg-public/reportlab/file/f094d273903a/CHANGES.md#l71
- https://hg.reportlab.com/hg-public/reportlab/rev/7f2231703dc7
- https://lists.debian.org/debian-lts-announce/2023/09/msg00037.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HMUJA5GZTPQ5WRYUCCK2GEZM4W43N7HH/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZQSFCID67K6BTC655EQY6MNOF35QI44/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMUJA5GZTPQ5WRYUCCK2GEZM4W43N7HH
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZQSFCID67K6BTC655EQY6MNOF35QI44
- https://nvd.nist.gov/vuln/detail/CVE-2020-28463
- https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145 ExploitRelease NotesThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-28463
- https://www.reportlab.com/docs/reportlab-userguide.pdf ProductVendor Advisory
Change history (0)
No recorded changes yet.