DirectorySecurity Advisories
Sign In
Security Advisories

CGA-2ww4-p3gf-fhhc

Published

Last updated

https://images.chainguard.dev/security/CGA-2ww4-p3gf-fhhc
Package

kibana-8

Latest Update
Fixed
Fixed Version

8.16.1-r0

Aliases
  • CVE-2024-4367
  • GHSA-wgrm-67xf-hhpq

Severity

8.8

High

CVSS V3

Summary

PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

Description

Impact

If pdf.js is used to load a malicious PDF, and PDF.js is configured with isEvalSupported set to true (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.

Patches

The patch removes the use of eval: https://github.com/mozilla/pdf.js/pull/18015

Workarounds

Set the option isEvalSupported to false.

References

https://bugzilla.mozilla.org/show_bug.cgi?id=1893645

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images