Server-Side Request Forgery (SSRF) - CVE-2019-17400
Published: October 22, 2019 / Updated: August 4, 2020
Vulnerability identifier: #VU33376
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17400
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
Affected software
py3-unoconv (Alpine package)
unoconv (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
unoconv (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, little endian
How to mitigate CVE-2019-17400
Install update from vendor's website.
py3-unoconv (Alpine package) - update to 0.8.2-r0
unoconv (Red Hat package) - update to 0.6-8.el7
unoconv (Red Hat package) - update to 0.6-8.el7