DomPDF vulnerability

Created on 15 December 2023, about 1 year ago
Updated 16 December 2023, about 1 year ago

Problem/Motivation

There is a security issue with dompdf.

https://github.com/dompdf/dompdf/releases/tag/v2.0.4

Steps to reproduce

composer audit
The new audit.abandoned setting (currently defaulting to "report" will default to "fail" in Composer 2.7, make sure to set it to "report" or "ignore" explicitly by then if you do not want this.
Found 2 security vulnerability advisories affecting 2 packages:
+-------------------+----------------------------------------------------------------------------------+
| Package           | dompdf/dompdf                                                                    |
| CVE               | CVE-2023-50262                                                                   |
| Title             | Denial of service caused by infinite recursion when parsing SVG images           |
| URL               | https://github.com/advisories/GHSA-3qx2-6f78-w2j2                                |
| Affected versions | <2.0.4                                                                           |
| Reported at       | 2023-12-13T23:09:04+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+

Proposed resolution

Require dompdf/dompdf 2.0.4 or higher

Remaining tasks

User interface changes

API changes

Data model changes

πŸ“Œ Task
Status

Fixed

Version

2.0

Component

Miscellaneous

Created by

πŸ‡ΊπŸ‡ΈUnited States bluegeek9

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024