Junglewise Threat Intelligence

CVE-2019-17400: PYSEC-2019-213 - The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.

CVE-2019-17400 · Severity: low · CVSS 3.1 · Published 2019-10-21

Vendors: PyPI.

Executive brief

unoconv is a command-line tool for converting documents between formats using LibreOffice. Versions before 0.9 mishandle file paths, allowing attackers to read arbitrary files from the server or access internal network resources, potentially exposing sensitive data or enabling reconnaissance of backend systems.

Technical details

unoconv before version 0.9 contains a Server-Side Request Forgery (SSRF) vulnerability caused by improper handling of untrusted pathnames. The flaw stems from the application's failure to sanitize file paths passed as input, particularly in the document update and conversion logic. An attacker can supply specially crafted file paths—including URLs or traversal sequences—that are processed by the underlying LibreOffice instance, leading to access of arbitrary local files or outbound requests to internal network resources. No authentication is required; the vulnerability is exploitable over the network through any interface that accepts file path input. The fix was addressed in version 0.9.0 by changing the default updateDocMode behavior and adding controls over link updating.

Affected products

  • unoconv unoconv before 0.9.0

Timeline

  • 2019-10-24: disclosed
  • 2019-09-17: patched: Fix merged in PR #510, released in version 0.9.0

References