{"id":"CGA-9fr4-h45h-6jhh","modified":"2026-07-31T08:12:12.827691494Z","published":"2025-11-04T03:39:46Z","withdrawn":"2026-07-31T08:12:12.827691348Z","upstream":["CVE-2024-4367","GHSA-wgrm-67xf-hhpq"],"references":[{"type":"WEB","url":"https://www.exploit-db.com/exploits/52273"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/releases/tag/v4.2.67"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-21/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-22/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-23/"},{"type":"REPORT","url":"https://github.com/gogs/gogs/issues/7928"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1893645"},{"type":"ARTICLE","url":"https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Aug/30"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-827383.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/4xxx/CVE-2024-4367.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4367"}],"affected":[{"package":{"name":"kibana-8-iamguarded","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/kibana-8-iamguarded?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.16.1-r0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:npm/pdfjs-dist@2.13.216","latest_event_status":"fixed","latest_event_timestamp":"2024-11-25T21:37:05Z","architecture":"aarch64","component_name":"pdfjs-dist","component_version":"2.13.216","component_type":"npm","component_location":"/usr/share/kibana/node_modules/pdfjs-dist/package.json"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-9fr4-h45h-6jhh.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}