CVE-2021-3902 - CVE House
Back to Database
Status published Critical CVE-2021-3902

Improper Restriction of XML External Entity Reference in dompdf/dompdf

Vulnerability Description

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issue affects all versions prior to 2.0.0. The vulnerability can be exploited even if the isRemoteEnabled option is set to false. It allows attackers to perform SSRF, disclose internal image files, and cause PHAR deserialization attacks.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3902

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dompdf/dompdf
Vulnerable Versions:
unspecified

Timeline

Official Publish: November 15th, 2024
Last Modified: November 18th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)