CVE-2021-3838
Last modified
CVE-2021-3838 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dompdf Project | Dompdf | < 2.0.0 |
References
- https://huntr.com/bounties/0bdddc12-ff67-4815-ab9f-6011a974f48eExploit, Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-3838?
How severe is CVE-2021-3838?
How do I fix CVE-2021-3838?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-38374OX App Suite through through 7.10.5 allows XSS via a crafted…5.4
- CVE-2021-38375OX App Suite through 7.10.5 allows XSS via the alt attribute…6.1
- CVE-2021-38376OX App Suite through 7.10.5 has Incorrect Access Control for…5.3
- CVE-2021-38377OX App Suite through 7.10.5 allows XSS via JavaScript code i…6.1
- CVE-2021-38378OX App Suite 7.10.5 allows Information Exposure because a ca…4.3
- CVE-2021-38379The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Inse…5.5
- CVE-2021-38380Live555 through 1.08 mishandles huge requests for the same M…7.5
- CVE-2021-38381Live555 through 1.08 does not handle MPEG-1 or 2 files prope…6.5
- CVE-2021-38382Live555 through 1.08 does not handle Matroska and Ogg files …6.5
- CVE-2021-38383OwnTone (aka owntone-server) through 28.1 has a use-after-fr…9.8
- CVE-2021-38384Serverless Offline 8.0.0 returns a 403 HTTP status code for …9.8
- CVE-2021-38385Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the re…7.5
Are you affected by CVE-2021-3838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
