React-PDF vulnerability allows unrestricted JavaScript execution
CVE-2024-34342

7.1HIGH

Key Information:

Vendor

Wojtekmaj

Status
Vendor
CVE Published:
7 May 2024

Badges

πŸ’° RansomwareπŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2024-34342?

A vulnerability exists in react-pdf, a popular library for displaying PDFs in React applications, particularly when integrated with PDF.js. If maliciously crafted PDFs are loaded using PDF.js with the 'isEvalSupported' configuration set to true (the default setting), there is a risk that attackers can execute arbitrary JavaScript code within the context of the hosting domain. This scenario can lead to significant security breaches, compromising user data and application integrity. The vulnerability has been addressed in updates 7.7.3 and 8.0.2 of react-pdf.

Affected Version(s)

react-pdf < 7.7.3 < 7.7.3

react-pdf >= 8.0.0, < 8.0.2 < 8.0.0, 8.0.2

News Articles

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js which could allow a threat actor to execute arbitrary code when opening a malicious

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • πŸ’°

    Used in Ransomware

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by GBHackers on Security

  • Vulnerability published

  • Vulnerability Reserved

.