Description
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
Remediation
References
https://security.netapp.com/advisory/ntap-20191017-0005/
https://www.npmjs.com/advisories/1095
Related Vulnerabilities
CVE-2020-7607 Vulnerability in npm package gulp-styledocco
CVE-2023-47322 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2023-40348 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2016-10707 Vulnerability in maven package org.webjars:jquery
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom__xmldom