HIGH 7.5 npm
jspdf vulnerable to Regular Expression Denial of Service (ReDoS)
GHSA-57f3-gghm-9mhc · CVE-2021-23353
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-23353
- WEB https://github.com/MrRio/jsPDF/pull/3091
- WEB https://github.com/MrRio/jsPDF/commit/d8bb3b39efcd129994f7a3b01b632164144ec43e
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1083289
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1083287
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-1083288
- WEB https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1083286
- WEB https://snyk.io/vuln/SNYK-JS-JSPDF-1073626
Ready to move
Start Securing
Free, no credit card | First findings in minutes