veraPDF Vulnerabilities and Affected Products
Vulnerabilities associated with veraPDF-library.
Products
Clear product- veraPDF-validation3 vulnerabilities
- veraPDF-library2 vulnerabilities
- veraPDF-parser2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Potential XXE (XML External Entity Injection) vulnerability in veraPDF CLIveraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability. This doesn't affect the standard validation and policy checks functionality, veraPDF's common use cases. Most veraPDF users don't insert any custom XSLT code into policy profiles, which are based on Schematron syntax rather than direct XSL transforms. For users who do, only l… CWE-611Nov 29, 2024 | CVSS2.3v4.0 | EPSS1.06% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-28109HIGH | Potential XSLT injection vulnerability when using policy filesveraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution (RCE) vulnerability. This vulnerability is fixed in 1.24.2. CWE-91Mar 28, 2024 | CVSS8.1v3.1 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |