Impact
If PDF.js is used to load a malicious PDF, and PDF.js is configured with enableScripting set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.
Patches
Workarounds
Set enableScripting to false or set a CSP.
References
https://bugzilla.mozilla.org/show_bug.cgi?id=2055885
Impact
If PDF.js is used to load a malicious PDF, and PDF.js is configured with
enableScriptingset to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.Patches
Workarounds
Set
enableScriptingtofalseor set a CSP.References
https://bugzilla.mozilla.org/show_bug.cgi?id=2055885