Insecure service configuration In weasyprint
Description
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if url_fetcher is configured to prevent access to files and URLs. This vulnerability has been patched in version 61.2.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 61.2-1 | ||
debian 14 | 61.2-1 | ||
pypi | 61.2 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.