Description
MetadataExtractor 2.1.0 allows stack consumption.
Remediation
References
https://github.com/drewnoakes/metadata-extractor-dotnet/pull/190
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
Related Vulnerabilities
CVE-2021-42357 Vulnerability in maven package org.apache.knox:gateway-service-knoxsso
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:activemq-fileserver
CVE-2022-2047 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2023-42503 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2022-23540 Vulnerability in maven package org.webjars.npm:jsonwebtoken