From Open Redirect to JavaScript Execution via CVE-2024-4367

Authors

DOI:

https://doi.org/10.14421/jiska.6353

Keywords:

CVE-2024-4367, PDF.js, Open Redirect, Vulnerability Chaining, SEO Poisoning

Abstract

This case study presents a forensically documented analysis of a multi-stage security incident involving CVE-2024-4367, an arbitrary JavaScript execution vulnerability in PDF.js. The incident occurred on one PKP Open Journal Systems (OJS) deployment. The observed chain involved an open redirect in the host platform's sign-out handler (CWE-601), a prefix-match URL validation weakness in the PDF.js viewer wrapper, and PDF.js font parsing behavior associated with CVE-2024-4367. The evidence demonstrates execution of attacker-controlled JavaScript in the viewer context and an SEO-poisoning effect; it does not establish a general vulnerability in all OJS, WordPress, Drupal, or enterprise deployments. CVSS scores are reported separately for the identified CVE and are not combined into a fabricated composite score. A defense-in-depth mitigation strategy combining reverse-proxy rules, library patches, and Content Security Policy was deployed and verified.

References

Barth, A. (2011). The Web origin concept (RFC 6454). Internet Engineering Task Force. https://datatracker.ietf.org/doc/html/rfc6454

Berners-Lee, T., Fielding, R., & Masinter, L. (2005). Uniform Resource Identifier (URI): Generic syntax (RFC 3986). Internet Engineering Task Force. https://datatracker.ietf.org/doc/html/rfc3986

Dinicola, E., & Luchaup, G. (2024). An empirical study of URL validation behaviors in web applications. In Proceedings of the 33rd USENIX Security Symposium (pp. 4137–4154). USENIX.

Exfil0. (2024). WEAPONIZING-CVE-2024-4367. GitHub. https://github.com/exfil0/WEAPONIZING-CVE-2024-4367

FIRST. (2023). Common Vulnerability Scoring System v4.0: Specification document. Forum of Incident Response and Security Teams. https://www.first.org/cvss/v4-0/

Ghaffarian, S. M., & Ghaffarian, S. (2024). A systematic literature review on automated vulnerability detection in web applications. ACM Computing Surveys, 56(5), 1–38.

Jovanovic, N., Kruegel, C., & Kirda, E. (2022). Pixy: A static analysis tool for detecting web application vulnerabilities. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (pp. 1523–1538). IEEE.

Kharraz, A., Robertson, W., & Kirda, E. (2022). Scribbleshots: Exploiting PDF-based JavaScript for large-scale attacks. In Proceedings of the 31st USENIX Security Symposium (pp. 3205–3222). USENIX.

MITRE. (2023a). T1189: Drive-by compromise. MITRE ATT&CK. https://attack.mitre.org/techniques/T1189/

MITRE. (2023b). MITRE ATT&CK v14. MITRE. https://attack.mitre.org/

MITRE. (2023c). T1203: Exploitation for client execution. MITRE ATT&CK. https://attack.mitre.org/techniques/T1203/

MITRE. (2024a). CWE-601: URL redirection to untrusted site. MITRE CWE. https://cwe.mitre.org/data/definitions/601.html

MITRE. (2024b). CWE-345: Insufficient verification of data authenticity. MITRE CWE. https://cwe.mitre.org/data/definitions/345.html

MITRE. (2024c). CWE-79: Improper neutralization of input during web page generation. MITRE CWE. https://cwe.mitre.org/data/definitions/79.html

Mozilla Foundation. (2024). MFSA 2024-26: Security vulnerabilities fixed in Firefox 126. Mozilla Foundation Security Advisories. https://www.mozilla.org/en-US/security/advisories/mfsa2024-26/

Munu, S., Zhang, J., & Li, Z. (2024). Vul chaining: Quantifying the composability of software vulnerabilities. In Proceedings of the 2024 IEEE Symposium on Security and Privacy (pp. 2312–2328). IEEE.

National Vulnerability Database. (2020). CVE-2020-8518: PHP object injection in OJS. NIST. https://nvd.nist.gov/vuln/detail/CVE-2020-8518

National Vulnerability Database. (2021). CVE-2021-4118: Deserialization vulnerability in OJS. NIST. https://nvd.nist.gov/vuln/detail/CVE-2021-4118

National Vulnerability Database. (2023). CVE-2023-42457: Path traversal in OJS. NIST. https://nvd.nist.gov/vuln/detail/CVE-2023-42457

National Vulnerability Database. (2024a). CVE-2024-4367: Arbitrary JavaScript execution in PDF.js. NIST. https://nvd.nist.gov/vuln/detail/CVE-2024-4367

npm. (2024). pdfjs-dist: PDF.js distribution for browsers. npm Registry. https://www.npmjs.com/package/pdfjs-dist

OWASP. (2024a). Content Security Policy cheat sheet. OWASP Cheat Sheet Series. https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html

OWASP. (2024b). Unvalidated redirects and forwards cheat sheet. OWASP Cheat Sheet Series. https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html

OWASP. (2024c). XSS Prevention cheat sheet. OWASP Cheat Sheet Series. https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html

Percival, C. (2023). JavaScript for hackers: A guide to the language and its security implications. No Starch Press.

PKP. (2023). pdfJsViewer plugin. GitHub. https://github.com/pkp/pdfJsViewer

PKP. (2024). Security advisories. GitHub. https://github.com/pkp/pkp-lib/security

PKP. (2025). OJS statistics. Public Knowledge Project. https://pkp.sfu.ca/ojs/ojs-usage/

Runeson, P., Höst, M., Rainer, A., & Cartlidge, B. (2022). Case study research in software engineering: Guidelines and practical examples (2nd ed.). Springer.

Shostack, A. (2023). Threat modeling: Designing for security (2nd ed.). Wiley.

Tang, S., Liu, H., & Li, Z. (2023). An empirical study of subdomain spoofing attacks on the web. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (pp. 1876–1890). ACM.

Wei, F., Li, S., Chandramohan, M., & Hao, R. (2022). A large-scale empirical study on the exploitability of DOM-based cross-site scripting. IEEE Transactions on Software Engineering, 48(5), 1592–1608.

Downloads

Published

2026-09-25

How to Cite

From Open Redirect to JavaScript Execution via CVE-2024-4367. (2026). JISKA (Jurnal Informatika Sunan Kalijaga), 11(3), 427-437. https://doi.org/10.14421/jiska.6353

Similar Articles

You may also start an advanced similarity search for this article.