{"id":"DRUPAL-CONTRIB-2022-048","details":"This module enables you to generate print versions of content.  \nSome installations of the module make use of the dompdf/dompdf third-party dependency.  \nSecurity vulnerabilities exist for versions of dompdf/dompdf \u003c 2.0.0\n\nSee the library release notes for more detail: \u003chttps://github.com/dompdf/dompdf/releases/tag/v2.0.0\u003e\n\n### Note on 3rd party vulnerabilities\n\nThis security advisory corresponds to a 3rd party vulnerability. Normally the Drupal Security Team would not issue advisories related to 3rd party code that is shipped separately from a module per our policy (most recent update is [PSA-2019-09-04](https://www.drupal.org/psa-2019-09-04)). In this case, because the module required a specific version and could not be updated without a change to the Drupal module we do issue an advisory.","modified":"2026-09-10T03:45:44.697460037Z","published":"2022-07-13T15:44:42Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2022-048"}],"affected":[{"package":{"name":"drupal/entity_print","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/entity_print?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.0"}],"database_specific":{"constraint":"\u003c2.6.0"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/entity_print/DRUPAL-CONTRIB-2022-048.json","affected_versions":"\u003c2.6.0"}}],"schema_version":"1.9.0","credits":[{"name":"Munavir P k","contact":["https://www.drupal.org/user/3604066"]},{"name":"szato","contact":["https://www.drupal.org/user/389677"]}]}