Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pdfjs-dist #1792

Closed
2 tasks done
VayneValerius opened this issue May 10, 2024 · 1 comment
Closed
2 tasks done

Update pdfjs-dist #1792

VayneValerius opened this issue May 10, 2024 · 1 comment
Labels
duplicate This issue or pull request already exists enhancement New feature or request

Comments

@VayneValerius
Copy link

Before you start - checklist

  • I understand that React-PDF does not aim to be a fully-fledged PDF viewer and is only a tool to make one
  • I have checked if this feature request is not already reported

Description

pdfjs-dist has a high level, arbitrary code injection vulnerability for versions <= 4.1.392. react-pdf is still using a 3.x.x version.

I can see that the isEvalSupported option has been set to false in the 8.0.2 release, which stops the vun from being possible, but for ci pipelines that use a tool like docker scout, it will fail deployments regardless.

Proposed solution

Update pdfjs-dist to 4.2.67

Alternatives

The alternative has already been implemented, which is fine for users who don't give a hoot about security.

Additional information

No response

@VayneValerius VayneValerius added the enhancement New feature or request label May 10, 2024
@wojtekmaj
Copy link
Owner

Duplicate of #1664

@wojtekmaj wojtekmaj marked this as a duplicate of #1664 May 10, 2024
@wojtekmaj wojtekmaj closed this as not planned Won't fix, can't repro, duplicate, stale May 10, 2024
@wojtekmaj wojtekmaj added the duplicate This issue or pull request already exists label May 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate This issue or pull request already exists enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants