Improper validation of integrity check value in jspdf - #VU60182

 

Improper validation of integrity check value in jspdf - #VU60182

Published: January 31, 2022


Vulnerability identifier: #VU60182
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to missing integrity check when loading the pdfobject lib from CDN in calls to output('pdfobjectnewwindow'). A remote attacker who is able to compromise CDN or perform MitM attack can inject arbitrary JS code and execute it victim's browser.


Affected software

jspdf

Remediation

Install updates from vendor's website.

jspdf - update to 2.5.1

External References

Related Security Bulletins