Skip to content

J2EE Misconfiguration: Data Transmission Without Encryption and J2EE Misconfiguration: Weak Access Permissions for EJB Methods in PDFjs

Moderate
Vignan-ACSE published GHSA-qcg4-cvv8-8jc2 Oct 18, 2021

Package

PDFjs (JavaScript)

Affected versions

<2.4.0

Patched versions

2.4.0

Description

Impact

Getting an exception when creating a new pdf.ExternalDocument(file) with this specific file only:
10.10 Food Handler Training Record A.pdf

Error [ERR_PACKAGE_PATH_NOT_EXPORTED]: Package subpath './lib/inflate.js' is not defined by "exports" in /app/node_modules/pdfjs/node_modules/pako/package.json

Patches

<2.4.6 Has the problem been patched? What versions should users upgrade to 2.4.6(Stable)

References

https://github.com/rkusa/pdfjs
https://mozilla.github.io/pdf.js/

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

No known CVE

Weaknesses