Описание
react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with isEvalSupported set to true (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2.
Ссылки
EPSS
Процентиль: 89%
0.05029
Низкий
7.1 High
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 7.1
github
почти 2 года назад
react-pdf vulnerable to arbitrary JavaScript execution upon opening a malicious PDF with PDF.js
EPSS
Процентиль: 89%
0.05029
Низкий
7.1 High
CVSS3
Дефекты
CWE-79