rpm package
opensuse/python-reportlab&distro=openSUSE Leap 15.2
pkg:rpm/opensuse/python-reportlab&distro=openSUSE%20Leap%2015.2
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-28463 | — | < 3.4.0-lp152.5.3.1 | 3.4.0-lp152.5.3.1 | Feb 18, 2021 | All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of repo |
- CVE-2020-28463Feb 18, 2021affected < 3.4.0-lp152.5.3.1fixed 3.4.0-lp152.5.3.1
All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of repo