HIGH

CVE-2019-17221

CVSS v3

7.5

HIGH

EPSS Score

13.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed.

Technical details

Published
11/5/2019

Frequently asked questions

What is CVE-2019-17221?

PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed.

Is CVE-2019-17221 actively exploited?

Active exploitation of CVE-2019-17221 has not been confirmed. The EPSS score is 13.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-17221?

CVE-2019-17221 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-17221 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.