#VU49286 Incorrect default permissions in gotenberg - CVE-2020-13452
Published: January 6, 2021
gotenberg
thecodingmachine
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to incorrect default permissions for the "/tini" file, which is writable by default by the gotenberg user. A remote attacker can overwrite the file using vulnerability #VU49284 and perform a denial of service attack or execute arbitrary code on the system.