Vulnerabilities/

Insecure Default Configuration in tesseract.js

Severity:
Medium

Description

Versions of tesseract.js prior to 1.0.19 default to using a third-party proxy. Requests may be proxied through crossorigin.me which clearly states is not suitable for production use. This may lead to instability and privacy violations.

Recommendation

Update the tesseract.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tesseract.js
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing