CVE-2025-29907
CVE-2025-29907
Título es
CVE-2025-29907
Mar, 18/03/2025 – 19:15
Tipo
CWE-400
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-29907
Descripción en
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitised image urls to the addImage method, a user can provide a harmful data-url that results in high CPU utilization and denial of service. Other affected methods are html and addSvgAsImage. The vulnerability was fixed in jsPDF 3.0.1.
18/03/2025
18/03/2025
Vector CVSS:4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Gravedad 4.0
8.70
Gravedad 4.0 txt
HIGH
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://github.com/parallax/jsPDF/commit/b167c43c27c466eb914b927885b06073708338df
https://github.com/parallax/jsPDF/security/advisories/GHSA-w532-jxjh-hjhj
Enviar en el boletín
Off
