React-PDF vulnerability allows unrestricted JavaScript execution
CVE-2024-34342
Key Information:
Badges
What is CVE-2024-34342?
A vulnerability exists in react-pdf, a popular library for displaying PDFs in React applications, particularly when integrated with PDF.js. If maliciously crafted PDFs are loaded using PDF.js with the 'isEvalSupported' configuration set to true (the default setting), there is a risk that attackers can execute arbitrary JavaScript code within the context of the hosting domain. This scenario can lead to significant security breaches, compromising user data and application integrity. The vulnerability has been addressed in updates 7.7.3 and 8.0.2 of react-pdf.
Affected Version(s)
react-pdf < 7.7.3 < 7.7.3
react-pdf >= 8.0.0, < 8.0.2 < 8.0.0, 8.0.2
News Articles
References
CVSS V3.1
Timeline
- π°
Used in Ransomware
- πΎ
Exploit known to exist
- π°
First article discovered by GBHackers on Security
Vulnerability published
Vulnerability Reserved
