{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "allows attacker to create or overwrite arbitrary files on the system",
    "tracking": {
      "current_release_date": "2026-08-11T17:01:34+00:00",
      "generator": {
        "date": "2026-08-11T17:01:34+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2023-35936",
      "initial_release_date": "2023-07-06T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T17:01:34+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "pandoc",
            "product": {
              "name": "pandoc",
              "product_id": "pandoc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/pandoc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "pandoc-common",
            "product": {
              "name": "pandoc-common",
              "product_id": "pandoc-common",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/pandoc-common"
              }
            }
          },
          {
            "category": "product_version",
            "name": "pandoc",
            "product": {
              "name": "pandoc",
              "product_id": "pandoc.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/pandoc?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pandoc as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:pandoc"
        },
        "product_reference": "pandoc",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pandoc-common as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:pandoc-common"
        },
        "product_reference": "pandoc-common",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "pandoc.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:pandoc.src"
        },
        "product_reference": "pandoc.src",
        "relates_to_product_reference": "rhel-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-35936",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "discovery_date": "2023-07-06T00:00:00+00:00",
      "notes": [
        {
          "category": "description",
          "text": "An arbitrary file write vulnerability was found in Haskell's Pandoc. This issue can be triggered by providing a specially crafted image element in the input when generating files using the --extract-media option or outputting to PDF format. This may allow an attacker to create or overwrite arbitrary files on the system, depending on the privileges of the process running pandoc.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-8:pandoc",
          "rhel-8:pandoc-common",
          "rhel-8:pandoc.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-35936"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35936"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-35936"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-8:pandoc",
            "rhel-8:pandoc-common",
            "rhel-8:pandoc.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L",
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhel-8:pandoc",
            "rhel-8:pandoc-common",
            "rhel-8:pandoc.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhel-8:pandoc",
            "rhel-8:pandoc-common",
            "rhel-8:pandoc.src"
          ]
        }
      ],
      "title": "allows attacker to create or overwrite arbitrary files on the system"
    }
  ]
}