EIQ-2019-0036
    
| 
     ID  | 
                
     EIQ-2019-0036  | 
        
| 
     CVE  | 
                |
| 
     Description  | 
                
     A crafted PDF file could allow malicious JavaScript injection  | 
        
| 
     Date  | 
                
     26 Sep 2019  | 
        
| 
     Severity  | 
                
     3 - HIGH  | 
        
| 
     CVSSv3 score  | 
                
     8.8  | 
        
| 
     Status  | 
                
     
  | 
        
| 
     Assessment  | 
                
     The vulnerability affects pdfjs-dist version 2.0.305. a sub-dependency of react-pdf version 3.0.6. The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. We test direct dependencies by scanning fixed builds, and then by checking the corresponding vulnerability reports to verify that they no longer include the addressed vulnerabilities.  | 
        
| 
     Mitigation  | 
                
     To mitigate the vulnerability, upgrade to react-pdf to version 4.0.0 or later.  | 
        
| 
     Affected versions  | 
                
     2.5.0 and earlier.  | 
        
| 
     Notes  | 
                
     For more information, see:  | 
        
< Back to all security issues and mitigation actions
In release notes 2.5.0
In release notes 2.6.0