CVE-2024-34342 is a cross-site scripting (XSS) vulnerability affecting react-pdf when used with PDF.js, allowing unrestricted JavaScript execution if PDF.js's isEvalSupported is set to its default true value. This high-severity vulnerability (CVSS 7.1) requires user interaction and a malicious PDF, potentially leading to high confidentiality and integrity impacts. While no active exploitation, public exploit code, or significant community discussion has been observed, patches are available in react-pdf versions 7.7.3 and 8.0.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wojtekmaj | React-Pdf | < 7.7.3, >= 8.0.0, < 8.0.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.