CVE-2024-28109

HIGH

Org.verapdf Core < 1.24.2 - Remote Code Execution

Title source: rule
STIX 2.1

Description

veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution (RCE) vulnerability. This vulnerability is fixed in 1.24.2.

Scores

CVSS v3 8.1
EPSS 0.0116
EPSS Percentile 78.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-91
Status published
Products (7)
org.verapdf/core 0 - 1.24.2Maven
org.verapdf/core-arlington 0 - 1.25.127Maven
org.verapdf/core-jakarta 0 - 1.24.2Maven
org.verapdf/verapdf-library 0 - 1.24.2Maven
org.verapdf/verapdf-library-arlington 0 - 1.25.127Maven
org.verapdf/verapdf-library-jakarta 0 - 1.24.2Maven
veraPDF/veraPDF-library < 1.24.2
Published Mar 28, 2024
Tracked Since Feb 18, 2026