« Volver al listado

CVE-2020-7740

Estado: ModificadaAlta (8.2)—💥 PoC

This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7740",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "report@snyk.io",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "report@snyk.io",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "node-pdf-generator",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-06T18:15:18.127",
  "references": [
    {
      "url": "https://github.com/darrenhaken/node-pdf-generator/blob/master/index.js%23L29",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-NODEPDFGENERATOR-609636",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://github.com/darrenhaken/node-pdf-generator/blob/master/index.js%23L29",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-NODEPDFGENERATOR-609636",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack."
    },
    {
      "lang": "es",
      "value": "Esto afecta a todas las versiones del paquete node-pdf-generator. Debido a la falta de comprobación de entrada del usuario y un saneamiento realizado al contenido proporcionado a node-pdf-generator, es posible para un atacante crear una URL que se pasará hacia un servidor externo permitiendo un ataque de tipo SSRF"
    }
  ],
  "lastModified": "2026-06-17T03:25:21.643",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:node-pdf-generator_project:node-pdf-generator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E05ED738-19D9-4995-AD1A-E9EC7148854B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "report@snyk.io"
}