CVE Vulnerabilities

CVE-2020-13451

Incomplete Cleanup

Published: Jan 07, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
GotenbergThecodingmachine*6.2.1 (including)

Potential Mitigations

References