{ "containers": { "cna": { "affected": [ { "product": "github.com/thecodingmachine/gotenberg", "vendor": "n/a", "versions": [ { "lessThan": "unspecified", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "value": "Elavon Payments (@etsms)" } ], "datePublic": "2021-02-26T00:00:00.000Z", "descriptions": [ { "lang": "en", "value": "All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as