VYPR
Critical severity9.8NVD Advisory· Published Jan 7, 2021· Updated Jun 17, 2026

CVE-2020-13452

CVE-2020-13452

Description

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

Affected products

3
  • cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*range: <=6.2.1
    • (no CPE)range: <=6.2.1
  • Gotenberg/Gotenbergdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.