CVE-2021-23353
Regular Expression Denial of Service (ReDoS)
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:R
Productos afectados
n/a · jspdf¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/MrRio/jsPDF/commit/d8bb3b39efcd129994f7a3b01b632164144ec43ehttps://github.com/MrRio/jsPDF/pull/3091https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1083289https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1083287https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-1083288https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1083286https://snyk.io/vuln/SNYK-JS-JSPDF-1073626