aws-solutions / enhanced-document-understanding-on-aws

Enhanced Document Understanding on AWS delivers an easy-to-use web application that ingests and analyzes documents, extracts content, identifies and redacts sensitive customer information, and creates search indexes from the analyzed data.
https://aws.amazon.com/solutions/implementations/enhanced-document-understanding-on-aws/
Apache License 2.0
34 stars 13 forks source link

Pdf.js vulnerability in v1.0.9 due to CVE-2024-34342 and CVE-2024-4367 #49

Closed mukitmomin closed 5 months ago

mukitmomin commented 5 months ago

Describe the bug

CVE-2024-34342 and CVE-2024-4367 are leading to npm audit scans failure, arising due to Pdf.js and react-pdf vulnerability.

To Reproduce In the source/ui directory run the command:

npm audit

Expected behavior No vulnerabilities

Please complete the following information about the solution:

To get the version of the solution, you can look at the description of the created CloudFormation stack. For example, "(SO0281) - Enhanced Document Understanding on AWS. Version v1.0.0".

Screenshots If applicable, add screenshots to help explain your problem (please DO NOT include sensitive information).

Additional context Add any other context about the problem here.

tabdunabi commented 5 months ago

Thank you for contacting us regarding CVE-2024-34342 and CVE-2024-4367. On May 30, 2024, Enhanced Document Understanding on AWS released version 1.0.10 and recommends customers upgrade to address these issues.