HIGH7.5
GHSA-57f3-gghm-9mhc
jspdf vulnerable to Regular Expression Denial of Service (ReDoS)
Quick fix
GHSA-57f3-gghm-9mhc — jspdf: upgrade to the fixed version with the command below.
npm install jspdf@2.3.1Details
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23353[ADVISORY]
- https://github.com/MrRio/jsPDF/pull/3091[WEB]
- https://github.com/MrRio/jsPDF/commit/d8bb3b39efcd129994f7a3b01b632164144ec43e[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1083289[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1083287[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-1083288[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1083286[WEB]
- https://snyk.io/vuln/SNYK-JS-JSPDF-1073626[WEB]