Description
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
Remediation
References
https://security.netapp.com/advisory/ntap-20191017-0005/
https://www.npmjs.com/advisories/1095
Related Vulnerabilities
CVE-2017-3156 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-oauth2
CVE-2017-16049 Vulnerability in npm package nodesqlite
CVE-2019-10806 Vulnerability in npm package vega-util
CVE-2019-16563 Vulnerability in maven package tech.andrey.jenkins:mission-control-view
CVE-2022-3171 Vulnerability in maven package com.google.protobuf:protobuf-java