rendertron
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting rendertronpage 1 of 1
- CVE-2017-18352MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.1.02018-12-17
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
- CVE-2017-18353HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.02018-12-17
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of…
- CVE-2017-18354HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.02018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
- CVE-2017-18355HIGHCVSS 7.5EG 7.5✓ Fixed in 1.1.02018-12-17
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
- CVE-2020-8902LOWCVSS 3.5EG 3.5✓ Fixed in 3.0.02021-02-23
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to,…
Check whether rendertron is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for rendertron CVEs against the assets you own.
Start Free Scan →