{ "schema_version": "1.4.0", "id": "GHSA-r97h-mg64-mcjr", "modified": "2022-05-24T22:01:28Z", "published": "2022-05-24T22:01:28Z", "aliases": [ "CVE-2021-23345" ], "summary": "Server-side Request Forgery in github.com/thecodingmachine/gotenberg", "details": "All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as