Bugzilla – Bug 1227659
VUL-0: CVE-2024-38526: pdoc: Polyfill Supply Chain Attack
Last modified: 2024-07-12 09:05:09 UTC
pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-38526 https://www.cve.org/CVERecord?id=CVE-2024-38526 https://github.com/mitmproxy/pdoc/pull/703 https://github.com/mitmproxy/pdoc/security/advisories/GHSA-5vgj-ggm4-fg62 https://sansec.io/research/polyfill-supply-chain-attack https://bugzilla.redhat.com/show_bug.cgi?id=2294734
SUSE is currently not shipping pdoc in its products.
we do not ship pdoc, so closing. To read more about the Polyfill supplay chain attack check bsc#1227687.