Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4j5-j8m6-jr6p

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information consistently reflects the verified certificate identity.

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information consistently reflects the verified certificate identity.

EPSS

Процентиль: 0%
0.00001
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information consistently reflects the verified certificate identity.

EPSS

Процентиль: 0%
0.00001
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-346