Description
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
Remediation
References
https://github.com/MrRio/jsPDF/commit/d8bb3b39efcd129994f7a3b01b632164144ec43e
https://github.com/MrRio/jsPDF/pull/3091
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1083289
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1083287
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-1083288
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1083286
https://snyk.io/vuln/SNYK-JS-JSPDF-1073626
Related Vulnerabilities
CVE-2022-25940 Vulnerability in maven package org.webjars.npm:lite-server
CVE-2023-35160 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2022-24289 Vulnerability in maven package org.apache.cayenne:cayenne-server
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_2.13
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty.ee9:jetty-ee9-servlets