Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[PDFx] PDF.js version used contains known vulnerabilities (2.12.313) #518

Open
bloemy7 opened this issue Jul 12, 2024 · 3 comments
Open
Assignees
Labels
bug Something isn't working

Comments

@bloemy7
Copy link

bloemy7 commented Jul 12, 2024

There is a known malicious code execution vulnerability in PDF.js: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34342
It's now been patched but we should upgrade the PDF.js version used in the package to make sure it's patched in this package.

@bloemy7 bloemy7 added the bug Something isn't working label Jul 12, 2024
@H4NSWORST
Copy link

Is this a vulnerability on all platforms Flutter/PDFx supports or only on web?

@windcloudit
Copy link

I also have a request to upgrade to PDF.JS version 4.4.168. Do you have any idea?

@GP4cK
Copy link

GP4cK commented Dec 10, 2024

This has been patched in #533
Make sure to run flutter pub run pdfx:install_web and that will update the pdf.js version in your index.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

5 participants