jsPDF icon indicating copy to clipboard operation
jsPDF copied to clipboard

CVE-2020-7691 Security Vulnerability Issue

Open parithibang opened this issue 1 year ago • 2 comments
trafficstars

With the latest version of jspdf:2.5.1 integrated into the project getting security vulnerability issue

CVE-2020-7691 EPSS: 0.17%CVSS: 6.1 In all versions of the package jspdf, it is possible to use <

  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7691
  • https://nvd.nist.gov/vuln/detail/CVE-2020-7691

Will there be a fix for this provided?

parithibang avatar Feb 05 '24 16:02 parithibang

Hey @parithibang, copying my response from https://github.com/eKoopmans/html2pdf.js/issues/677:

Thanks for the heads up!

The good news is that the fromHTML method reported in CVE-2020-7691 no longer exists in jsPDF:

I think this should be safe to close, but I'll leave that to the judgment of @parallax.

eKoopmans avatar Feb 07 '24 03:02 eKoopmans

This issue is stale because it has been open 90 days with no activity. It will be closed soon. Please comment/reopen if this issue is still relevant.

github-actions[bot] avatar May 08 '24 01:05 github-actions[bot]