Junglewise Threat Intelligence

CVE-2024-34342: react-pdf arbitrary JavaScript execution via malicious PDF

CVE-2024-34342 · Severity: low · CVSS 3.1 · Published 2024-05-07

Executive brief

react-pdf is a React library for rendering PDF documents in web applications. When processing a malicious PDF file with PDF.js configured with its default settings, an attacker can execute arbitrary JavaScript code in the context of the hosting web domain, potentially allowing theft of user data or hijacking of user sessions.

Technical details

This vulnerability is a cross-site scripting (XSS) flaw in PDF.js (the underlying PDF rendering engine) that react-pdf depends on. When isEvalSupported is set to true (the default), PDF.js uses eval() to execute attacker-controlled JavaScript code embedded within malicious PDF files. The attack requires a user to open a crafted PDF in an application using react-pdf, but no authentication is required. An attacker who can serve a malicious PDF or trick a user into opening one can execute arbitrary JavaScript in the user's browser within the hosting domain's security context. Patches are available in react-pdf 7.7.3 and 8.0.2, which disable isEvalSupported by default.

Affected products

  • wojtekmaj react-pdf all versions up to 7.7.2 and 8.0.0 through 8.0.1

Timeline

  • 2024-05-07: disclosed
  • 2024-05-07: patched: Patches released for versions 7.7.3 and 8.0.2

References