Description
Versions of tesseract.js prior to 1.0.19 default to using a third-party proxy. Requests may be proxied through crossorigin.me which clearly states is not suitable for production use. This may lead to instability and privacy violations.
Recommendation
Update the tesseract.js package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.19
- Patched version(s): 1.0.19
References
Related Issues
- Insecure password handling vulnerability in Strapi - CVE-2021-46440
- Configuration Override in helmet-csp - Vulnerability
- @nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys - Vulnerability
- angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend - CVE-2023-28444
You might also like:
- Tags:
- npm
- tesseract.js
Anything's wrong? Let us know Last updated on January 09, 2023


