漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the ‘--sandbox’ option or ‘pandoc-server’ can mitigate such vulnerabilities. Using pandoc with an external ‘--pdf-engine’ can also enable SSRF vulnerabilities, such as CVE-2022-35583 in wkhtmltopdf.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pandoc 安全漏洞
Vulnerability Description
Pandoc是一个Haskell库,用于从一种标记格式转换为另一种标记格式,以及使用该库的命令行工具。 Pandoc 3.6.4版本存在安全漏洞,该漏洞源于服务端请求伪造,可能导致基础设施被入侵。
CVSS Information
N/A
Vulnerability Type
N/A