CVE-2024-28109
EUVD-2024-175628.03.2024, 14:15
veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution (RCE) vulnerability. This vulnerability is fixed in 1.24.2.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| verapdf | verapdf-library | 𝑥 < 1.24.2 | ADP |
References