EIQ-2019-0036
|
ID |
EIQ-2019-0036 |
|
CVE |
|
|
Description |
A crafted PDF file could allow malicious JavaScript injection |
|
Date |
26 Sep 2019 |
|
Severity |
3 - HIGH |
|
CVSSv3 score |
8.8 |
|
Status |
|
|
Assessment |
The vulnerability affects pdfjs-dist version 2.0.305. a sub-dependency of react-pdf version 3.0.6. The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. We test direct dependencies by scanning fixed builds, and then by checking the corresponding vulnerability reports to verify that they no longer include the addressed vulnerabilities. |
|
Mitigation |
To mitigate the vulnerability, upgrade to react-pdf to version 4.0.0 or later. |
|
Affected versions |
2.5.0 and earlier. |
|
Notes |
For more information, see: |
< Back to all security issues and mitigation actions
In release notes 2.5.0
In release notes 2.6.0