Description
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3273-1 | libitext5-java security update |
Debian DSA |
DSA-5323-1 | libitext5-java security update |
EUVD |
EUVD-2021-2524 | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java. |
Github GHSA |
GHSA-gv87-q66h-4277 | Command injection in itext7-core |
References
History
Thu, 26 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-25T17:20:11.587Z
Reserved: 2021-11-01T00:00:00.000Z
Link: CVE-2021-43113
Updated: 2024-08-04T03:47:13.596Z
Status : Modified
Published: 2021-12-15T07:15:07.453
Modified: 2026-02-25T18:16:53.763
Link: CVE-2021-43113
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA