pdfkit
Uses wkhtmltopdf to create PDFs using HTML
Activity
- Latest release
- 3y ago
- Total releases
- 40
- Cadence
- ~15 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- May 21, 2010
| Version | Released | |
|---|---|---|
0.8.7.3
patch
| ||
0.8.7.2
patch
| ||
0.8.7.1
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.7
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.6
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.5
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.4.3.2
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.4.3.1
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.4.2
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.4
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.4.1
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.3
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.2
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.1
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.6.2
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.6.1
minor
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.5.4
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.5.3
patch
1 CVE
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev | ||
0.5.2
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.1
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.6
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.5
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.4
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.3
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.2
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.1
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.3.3
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.3.2
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.3.1
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.3
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.2.2
patch
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2022-25765
GHSA-rhwx-hjx2-x4qr
Sep 10, 2022
PDFKit vulnerable to Command Injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 26 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.1
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.4.1
0.8.4.2
0.8.4.3.1
0.8.4.3.2
0.8.5
0.8.6
0.8.7
0.8.7.1
Fixed in
0.8.7.2
References
Updated Feb 19, 2024 · Source: OSV.dev
CVE-2013-1607
GHSA-39v7-xpq4-8884
May 05, 2022
PDFKit Improper Input Validation vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
+ 8 more Show less
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.5.0
0.5.1
0.5.2
Fixed in
0.5.3
References
Updated Feb 16, 2024 · Source: OSV.dev |