com.drewnoakes:metadata-extractor
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.drewnoakes:metadata-extractorpage 1 of 1
- CVE-2022-24613MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.18.02022-02-24
vulnerable: 2.10.0 ... 2.9.1 (18 versions)
metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use…
- CVE-2022-24614MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.18.02022-02-24
vulnerable: 2.10.0 ... 2.9.1 (18 versions)
When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of se…
Check whether com.drewnoakes:metadata-extractor is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.drewnoakes:metadata-extractor CVEs against the assets you own.
Start Free Scan →