Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)
Vulnerability Description
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful PNG file that results in high CPU utilization and denial of service. The vulnerability was fixed in jsPDF 3.0.2.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
jsPDF 安全漏洞
Vulnerability Description
jsPDF是Parallax开源的一款基于JavaScript的PDF文档生成库。 jsPDF 3.0.2之前版本存在安全漏洞,该漏洞源于addImage方法未对输入进行充分验证,可能导致CPU资源耗尽和拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A