Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Withdrawn: Arbitrary Code Execution in static-eval #2342

Closed
Vinod-Telang1 opened this issue Oct 4, 2021 · 9 comments
Closed

Withdrawn: Arbitrary Code Execution in static-eval #2342

Vinod-Telang1 opened this issue Oct 4, 2021 · 9 comments

Comments

@Vinod-Telang1
Copy link

pdfmake module having vulnerabilities with following error
Withdrawn: Arbitrary Code Execution in static-eval

pdf-make

Team, can you please provide the solution for this?

@liborm85
Copy link
Collaborator

liborm85 commented Oct 4, 2021

Version of pdfmake is?

@Vinod-Telang1
Copy link
Author

@liborm85
its occurring for all from 0.1.70 to latest one 0.2.2

@liborm85
Copy link
Collaborator

liborm85 commented Oct 5, 2021

Vulnerability is only in version 0.1.x.
Version 0.2.x does not contain any vulnerability. Package svg-to-pdfkit install own pdfkit library, but this library is not used by svg-to-pdfkit or pdfmake.

@AxelRothe
Copy link

Can we please fix this? NPM will try to fix it by alternatively installing 0.1.72 or 0.2.2. depending on what you have installed.

@liborm85
Copy link
Collaborator

liborm85 commented Oct 7, 2021

How I solve it in pdfmake if vulnerable pdfkit is dependency in svg-to-pdfkit library and this pdfkit is not used by pdfmake or svg-to-pdfkit?

@AxelRothe
Copy link

The maintainers need to escalate this to svg-to-pdfkit as one of their dependents. If a package is installed but not used it should be removed by the dependencies maintainers.

@liborm85
Copy link
Collaborator

liborm85 commented Oct 7, 2021

You can create issue here.

@Vinod-Telang1
Copy link
Author

You can create issue here.

Opened
alafr/SVG-to-PDFKit#151

@liborm85
Copy link
Collaborator

liborm85 commented Nov 6, 2021

svg-to-pdfkit is in version pdfmake 0.2.3 build-in (without pdfkit dependency) ce50aeb.

@liborm85 liborm85 closed this as completed Nov 6, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants