Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1756 | veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution (RCE) vulnerability. This vulnerability is fixed in 1.24.2. |
Github GHSA |
GHSA-qxqf-2mfx-x8jw | veraPDF has potential XSLT injection vulnerability when using policy files |
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:48:48.254Z
Reserved: 2024-03-04T14:19:14.059Z
Link: CVE-2024-28109
Updated: 2024-08-02T00:48:48.254Z
Status : Deferred
Published: 2024-03-28T14:15:13.863
Modified: 2026-06-17T07:20:59.123
Link: CVE-2024-28109
No data.
OpenCVE Enrichment
No data.
-
CWE-91
XML Injection (aka Blind XPath Injection)
EUVD
Github GHSA