CVE-2024-22641: Malicious File Upload
Published May 28, 2024
·Updated
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
Affected Software
2 affected components
Tcpdf Project Tcpdf<=6.7.4
TCPDF TCPDF<6.6.5
Event History
May 28, 2024
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22641?
CVE-2024-22641 is classified as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2024-22641?
To fix CVE-2024-22641, upgrade TCPDF to version 6.6.6 or later.
3
What types of files can exploit CVE-2024-22641?
CVE-2024-22641 can be exploited by parsing untrusted SVG files.
4
Who is affected by CVE-2024-22641?
Any user running TCPDF version 6.6.5 or earlier is affected by CVE-2024-22641.
5
What is the main impact of CVE-2024-22641?
The main impact of CVE-2024-22641 is the potential for a ReDoS attack, leading to application downtime.