Embedded malicious code (backdoor) in pdoc - CVE-2024-38526
Published: October 3, 2024
Vulnerability identifier: #VU98008
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38526
CWE-ID: CWE-506
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to documentation generated with `pdoc --math` is linked to JavaScript files
from polyfill.io. The polyfill.io CDN has been sold and now serves
malicious code.
Affected software
pdoc
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Siebel CRM End User
ghc-pandoc
ghc-pandoc-devel
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Package Hub 15
openSUSE Leap
Siebel CRM End User
ghc-pandoc
ghc-pandoc-devel
How to mitigate CVE-2024-38526
Install updates from vendor's website.
pdoc - update to 14.5.1
ghc-pandoc - update to 3.1.11.1-150500.11.6.1
ghc-pandoc-devel - update to 3.1.11.1-150500.11.6.1
ghc-pandoc - update to 3.1.11.1-150500.11.6.1
ghc-pandoc-devel - update to 3.1.11.1-150500.11.6.1