Embedded malicious code (backdoor) in pdoc - CVE-2024-38526

 

Embedded malicious code (backdoor) in pdoc - CVE-2024-38526

Published: October 3, 2024


Vulnerability identifier: #VU98008
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38526
CWE-ID: CWE-506
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the application.

The vulnerability exists due to documentation generated with `pdoc --math` is linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code.


Affected software

pdoc
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Siebel CRM End User
ghc-pandoc
ghc-pandoc-devel

How to mitigate CVE-2024-38526

Install updates from vendor's website.

pdoc - update to 14.5.1
ghc-pandoc - update to 3.1.11.1-150500.11.6.1
ghc-pandoc-devel - update to 3.1.11.1-150500.11.6.1

External References

Related Security Bulletins