VYPR

rpm package

opensuse/python-reportlab&distro=openSUSE Leap 15.2

pkg:rpm/opensuse/python-reportlab&distro=openSUSE%20Leap%2015.2

Vulnerabilities (1)

  • CVE-2020-28463Feb 18, 2021
    affected < 3.4.0-lp152.5.3.1fixed 3.4.0-lp152.5.3.1

    All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of repo