VDB

CVE-2020-21365

CVE-2020-21365 PUBLISHED

Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.

EPSS 0.46% · 64.3th percentile

Risk Scores

EPSS Score
0.46%
64.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSwkhtmltopdf0, 0.12.2.4-1
Ubuntu:20.04:LTSwkhtmltopdf0, 0.12.5-1, 0.12.5-1build1
Ubuntu:Pro:18.04:LTSwkhtmltopdf0, 0.12.3.2-3, 0.12.4-1
Ubuntu:Pro:14.04:LTSwkhtmltopdf0, 0.9.9-4

Exploit Intelligence

…and 26 more exploits

Timeline

  • Aug 15, 2022 CVE Published
  • Aug 16, 2022 EPSS Score
  • Oct 1, 2022 EPSS Score
  • Nov 16, 2022 EPSS Score
  • Jan 1, 2023 EPSS Score
  • Feb 16, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 19, 2023 EPSS Score
  • Jul 4, 2023 EPSS Score
  • Aug 19, 2023 EPSS Score
  • Oct 4, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›