Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An att…
High CVSS 7.5
Summary
Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/bpampuch/pdfmake/commit/741169634bf07730e010cd77477b6cc038e846ed Patch
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-14101887
- https://security.snyk.io/vuln/SNYK-JS-PDFMAKE-10223297 Third Party Advisory
Timeline
- nvd_ingest NVD