-
-
Notifications
You must be signed in to change notification settings - Fork 422
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical Security Vulnerability in dependency package "pdfjs" #1109
Comments
Did you search? Multiple issues cover this already |
Yes. But I don't see any of them clearly explaining how to overcome the vulnerability. The closest thing I have seen is ppl mentioning to set the |
I agree it's not clear how to resolve this security issue. Is there a patch or update coming? |
Does anyone know what is the effort to update the dependency to pdfjs 4.x? |
... #1105 |
Should be closed |
Closing @shamoon |
Bug Report or Feature Request (mark with an
x
)The latest version of
ng2-pdf-viewer
(10.2.2) has a dependency topdfjs-dist
version3.11.x
which has recently been discovered to have an extremely critical vulnerability, allowing attacks on the domain.The latest version of
pdfjs-dist
has remediated that vulnerability, I am wondering if a new version ofng2-pdf-viewer
coming out soon that uses the latest version and remediates this vulnerability?The text was updated successfully, but these errors were encountered: