Incomplete cleanup in gotenberg - CVE-2020-13451
Published: January 6, 2021
gotenberg
thecodingmachine
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to software does not remove temporary files created during previous file uploads. A remote attacker can upload a specially crafted file that will overwrite libreoffice config (profile) files and execute arbitrary code on the system using libreoffice macros.