CVE-2022-46161
Code injection in pdfmake
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Dec 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
bpampuch · pdfmakeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →