Skip to content

Improper Handling of Exceptional Conditions inn metadata-extractor

Moderate severity GitHub Reviewed Published Feb 25, 2022 to the GitHub Advisory Database • Updated Feb 9, 2023

Package

maven com.drewnoakes:metadata-extractor (Maven)

Affected versions

< 2.18.0

Patched versions

2.18.0

Description

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.

References

Published by the National Vulnerability Database Feb 24, 2022
Published to the GitHub Advisory Database Feb 25, 2022
Reviewed Mar 7, 2022
Last updated Feb 9, 2023

Severity

Moderate
5.5
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Weaknesses

CVE ID

CVE-2022-24613

GHSA ID

GHSA-p5pg-wm9q-8v6r

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.