Description
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
Remediation
References
https://github.com/MrRio/jsPDF/commit/d8bb3b39efcd129994f7a3b01b632164144ec43e
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1083289
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1083286
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1083287
https://snyk.io/vuln/SNYK-JS-JSPDF-1073626
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-1083288
https://github.com/MrRio/jsPDF/pull/3091
Related Vulnerabilities
CVE-2010-2276 Vulnerability in npm package dojo
CVE-2021-42567 Vulnerability in maven package org.apereo.cas:cas-server-core-services
CVE-2020-36379 Vulnerability in npm package aaptjs
CVE-2017-2582 Vulnerability in maven package org.keycloak:keycloak-saml-core
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents.client5:httpclient5