Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-23792

Опубликовано: 06 мая 2022
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 7.3

Описание

The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

focal

ignored

end of standard support, was needs-triage
impish

ignored

end of life
jammy

needs-triage

kinetic

ignored

end of life, was needs-triage

Показывать по

7.5 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
почти 4 года назад

The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.

CVSS3: 7.3
debian
почти 4 года назад

The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 ar ...

CVSS3: 9.8
github
почти 4 года назад

External Entity Reference in TwelveMonkeys ImageIO

7.5 High

CVSS2

7.3 High

CVSS3