MSA-21-0035: Arbitrary file read by site administrators via LaTeX preamble
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
Severity/Risk: | Serious |
Versions affected: | 3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions |
Versions fixed: | 3.11.3, 3.10.7 and 3.9.10 |
Reported by: | raisin_bugbou |