This release fixes three security issues.
What's Changed
- Fix PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton children) vulnerability.
- Fix Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions vulnerability.
- Fix PDF Object Injection via Unsanitized Input in addJS Method vulnerability.
- Add "default" property to export section in package.json by @stefan-schweiger in #3953
New Contributors
- @stefan-schweiger made their first contribution in #3953
Full Changelog: v4.1.0...v4.2.0