CVE-2022-41957
Last modified
CVE-2022-41957 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. The issue has been patched in muhammara version 3.4.0 and the fix has been backported to version 2.6.2. As a workaround, do not process files from untrusted sources. If using hummus, replace the package with muhammara.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Muhammara Project | Muhammara | < 2.6.2 |
| Muhammara Project | Muhammara | >= 3.0.0, < 3.3.0 |
| Hummus Project | Hummus | All versions |
References
- https://github.com/julianhille/MuhammaraJS/pull/235Issue Tracking, Patch, Third Party Advisory
- https://github.com/julianhille/MuhammaraJS/pull/238Issue Tracking, Patch, Third Party Advisory
- https://github.com/julianhille/MuhammaraJS/pull/235Issue Tracking, Patch, Third Party Advisory
- https://github.com/julianhille/MuhammaraJS/pull/238Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41957?
How severe is CVE-2022-41957?
How do I fix CVE-2022-41957?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-41951OroPlatform is a PHP Business Application Platform (BAP) des…9.8
- CVE-2022-41952Synapse before 1.52.0 with URL preview functionality enabled…5.3
- CVE-2022-41953Git GUI is a convenient graphical tool that comes with Git f…7.8
- CVE-2022-41954MPXJ is an open source library to read and write project pla…3.3
- CVE-2022-41955Autolab is a course management service, initially developed …8.8
- CVE-2022-41956Autolab is a course management service, initially developed …6.5
- CVE-2022-41958super-xray is a web vulnerability scanning tool. Versions pr…7.8
- CVE-2022-4196The Multi Step Form WordPress plugin before 1.7.8 does not s…4.8
- CVE-2022-41960BigBlueButton is an open source web conferencing system. Ver…4.3
- CVE-2022-41961BigBlueButton is an open source web conferencing system. Ver…4.3
- CVE-2022-41962BigBlueButton is an open source web conferencing system. Ver…2.7
- CVE-2022-41963BigBlueButton is an open source web conferencing system. Ver…3.1
Are you affected by CVE-2022-41957?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
