CVE-2024-4367: Stored XSS via PDFjs

Published May 7, 2024
·
Updated

Impact If pdf.js is used to load a malicious PDF, and PDF.js is configured with isEvalSupported set to true (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.

Patches The patch removes the use of eval: https://github.com/mozilla/pdf.js/pull/18015

Workarounds Set the option isEvalSupported to false.

References https://bugzilla.mozilla.org/showbug.cgi?id=1893645

Other sources

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.

Mozilla

Mitigations were made to take care of vulnerability in PDF.js CVE-2024-4367.

GitLab

Affected Software

60 affected componentsFixes available
redhat/firefox<115.11
115.11
redhat/thunderbird<115.11
115.11
debian/firefox
130.0.1-1
debian/firefox-esr
115.14.0esr-1~deb11u1115.15.0esr-1~deb11u1115.14.0esr-1~deb12u1115.15.0esr-1~deb12u1115.15.0esr-1
debian/odoo
14.0.0+dfsg.2-7+deb11u216.0.0+dfsg.2-3
debian/thunderbird
1:115.12.0-1~deb11u11:115.15.0-1~deb11u11:115.12.0-1~deb12u11:115.15.0-1~deb12u11:128.2.0esr-11:128.2.1esr-1
IBM Cognos Analytics<=12.0.0-12.0.3
IBM Cognos Analytics<=11.2.0-11.2.4 FP4
Mozilla Thunderbird<115.11
115.11
Mozilla Firefox<126
126
Mozilla Firefox ESR<115.11
115.11
Mozilla Firefox<115.11.0
Mozilla Firefox<126.0
Mozilla Thunderbird<115.11.0
Debian Debian Linux=10.0
Open-Xchange Open-xchange Appsuite Frontend<7.10.6
Open-Xchange Open-xchange Appsuite Frontend=7.10.6
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision10
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision11
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision12
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision13
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision14
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision15
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision16
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision17
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision18
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision19
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision20
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision21
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision22
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision23
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision24
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision25
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision26
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision27
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision28
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision29
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision3
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision30
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision31
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision32
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision33
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision34
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision35
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision36
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision37
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision38
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision39
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision4
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision40
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision41
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision42
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision43
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision44
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision5
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision6
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision7
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision8
Open-Xchange Open-xchange Appsuite Frontend=7.10.6-revision9
npm/pdfjs-dist<=4.1.392
4.2.67

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/firefox to a version that resolves this vulnerability.

    Fixed in 130.0.1-1
  2. Upgrade

    Upgrade debian/firefox-esr to a version that resolves this vulnerability.

    Fixed in 115.14.0esr-1~deb11u1Fixed in 115.15.0esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 115.15.0esr-1~deb12u1Fixed in 115.15.0esr-1
  3. Upgrade

    Upgrade debian/odoo to a version that resolves this vulnerability.

    Fixed in 14.0.0+dfsg.2-7+deb11u2Fixed in 16.0.0+dfsg.2-3
  4. Upgrade

    Upgrade debian/thunderbird to a version that resolves this vulnerability.

    Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.15.0-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.15.0-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.2.1esr-1
  5. Upgrade

    Upgrade Thunderbird to a version that resolves this vulnerability.

    Fixed in 115.11
  6. Upgrade

    Upgrade Firefox to a version that resolves this vulnerability.

    Fixed in 126
  7. Upgrade

    Upgrade Firefox ESR to a version that resolves this vulnerability.

    Fixed in 115.11
  8. Upgrade

    Upgrade npm/pdfjs-dist to a version that resolves this vulnerability.

    Fixed in 4.2.67
  9. Upgrade

    Upgrade redhat/firefox to a version that resolves this vulnerability.

    Fixed in 115.11
  10. Upgrade

    Upgrade redhat/thunderbird to a version that resolves this vulnerability.

    Fixed in 115.11
  11. Configuration

    Set PDF.js option `isEvalSupported` to `false` to prevent attacker-controlled JavaScript execution via PDF handling (CVE-2024-4367).

    PDF.js isEvalSupported = false

Event History

May 7, 2024
Advisory Published
via GitHub·10:25 AM
May 14, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·06:37 PM
DescriptionSeverityAffected Software
Jun 30, 2024
Data Sourced
via Launchpad·08:05 AM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·08:16 AM
RemedyDescriptionSeverityAffected Software
Apr 22, 2025
Exploit Published
12:00 AM
Known Exploited
05:57 PM
Apr 22, 2026
Data Sourced
via GitLab·08:52 AM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-4367?

CVE-2024-4367 is assigned a critical severity due to the potential execution of unrestricted attacker-controlled JavaScript.

2

How do I fix CVE-2024-4367?

To fix CVE-2024-4367, update to the latest version of affected software, such as Firefox or Thunderbird, which includes the necessary patches.

3

What versions are affected by CVE-2024-4367?

CVE-2024-4367 affects versions of Firefox ESR up to 115.11 and Thunderbird up to 115.11.

4

What is the main risk associated with CVE-2024-4367?

The main risk of CVE-2024-4367 is that it allows attackers to execute malicious JavaScript within the context of the hosting domain.

5

Who is impacted by CVE-2024-4367?

Users of Mozilla Firefox ESR and Thunderbird, especially those utilizing pdf.js with eval support enabled, are at risk from CVE-2024-4367.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203