RSS   Vulnerabilities for 'Rendertron'   RSS

2021-02-23
 
CVE-2020-8902

CWE-918
 

 
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.

 
2018-12-17
 
CVE-2017-18355

CWE-200
 

 
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.

 
 
CVE-2017-18354

CWE-22
 

 
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.

 
 
CVE-2017-18353

CWE-noinfo
 

 
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.

 
 
CVE-2017-18352

CWE-79
 

 
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.

 

 >>> Vendor: Google 95 Products
Cardboard
Toolbar
Chrome
Desktop
TALK
Mini search appliance
Search appliance
Api search
Earth
Web toolkit
Custom search engine
Calendar events
Picasa
KML
Android sdk
Google apps
Gears
Android browser
Android
V8
Google sketchup
Chrome os
App engine python sdk
Idapython
Cr-48 chromebook
Chr2000ome
Sketchup
Chrome2000
Chrom2000e
Bionic
Blink
Tunnelblick
Mod pagespeed
Email
Admob
Checkout-php
Cityhash
Android sdk tools
Chrome frame
Frame
Google authenticator
Authenticator
Glass
Android api
Search appliance software
Android debug bridge
Android sdk platform tools
Nexus 7
Play services sdk
Kubernetes
Android one
Sfntly
GRPC
Google i/o 2017
News and weather
Protobuf
Gmail
Boringssl
Santa
Chromecast firmware
Home firmware
Rendertron
Kubernetes engine
Guava
Tensorflow
Snappy
Nexus 7 firmware
Nexus 9 firmware
Voice builder
Cloud messaging notification
Nest cam iq indoor firmware
Fscrypt
Gizmo5
Closure library
Openthread
Chrome-launcher
Asylo
Go-tpm
Brotli
Gerrit
Flatbuffers
Secret manager provider for secret store csi driver
Slashify
Exposure notifications verification server
Bazel
Cloud iot device sdk for embedded c
Bindiff
Angle
Exposure notification verification server
Google-protobuf
Protobuf-java
Protobuf-kotlin
Fuchsia
Go-attestation
Oauth client library for java


Copyright 2024, cxsecurity.com

 

Back to Top