An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 13 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfmake Project
Pdfmake Project pdfmake |
|
| CPEs | cpe:2.3:a:pdfmake_project:pdfmake:0.2.9:*:*:*:*:*:*:* | |
| Vendors & Products |
Pdfmake Project
Pdfmake Project pdfmake |
Mon, 26 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-26T19:31:26.533Z
Reserved: 2024-02-07T00:00:00
Link: CVE-2024-25180
Updated: 2024-08-01T23:36:21.792Z
Status : Analyzed
Published: 2024-02-29T18:15:16.520
Modified: 2025-05-13T14:46:15.803
Link: CVE-2024-25180
No data.
OpenCVE Enrichment
No data.
Weaknesses