« Volver al listado

CVE-2024-1648

Estado: ModificadaAlta (7.5)—

electron-pdf version 20.0.0 allows an external attacker to remotely obtain

arbitrary local files. This is possible because the application does not

validate the HTML content entered by the user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1648",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1648",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-20T15:31:00.756065Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "help@fluidattacks.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "help@fluidattacks.com",
      "affectedData": [
        {
          "vendor": "electron-pdf",
          "product": "electron-pdf",
          "versions": [
            {
              "status": "affected",
              "version": "20.0.0"
            }
          ],
          "packageName": "electron-pdf",
          "collectionURL": "https://registry.npmjs.org",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:fraserxu:electron-pdf:*:*:*:*:*:*:*:*"
          ],
          "vendor": "fraserxu",
          "product": "electron-pdf",
          "versions": [
            {
              "status": "affected",
              "version": "20.0.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-20T01:15:07.943",
  "references": [
    {
      "url": "https://fluidattacks.com/advisories/drake",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "help@fluidattacks.com"
    },
    {
      "url": "https://www.npmjs.com/package/electron-pdf/",
      "tags": [
        "Product"
      ],
      "source": "help@fluidattacks.com"
    },
    {
      "url": "https://fluidattacks.com/advisories/drake",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.npmjs.com/package/electron-pdf/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "help@fluidattacks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "electron-pdf version 20.0.0 allows an external attacker to remotely obtain\n\narbitrary local files. This is possible because the application does not\n\nvalidate the HTML content entered by the user."
    },
    {
      "lang": "es",
      "value": "electron-pdf versión 20.0.0 permite a un atacante externo obtener de forma remota archivos locales arbitrarios. Esto es posible porque la aplicación no valida el contenido HTML ingresado por el usuario."
    }
  ],
  "lastModified": "2026-06-17T07:04:42.170",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fraserxu:electron-pdf:20.0.0:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F174B14E-92BA-4307-8052-1519F4EC45AA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "help@fluidattacks.com"
}