Description
MetadataExtractor 2.1.0 allows stack consumption.
Remediation
References
https://github.com/drewnoakes/metadata-extractor-dotnet/pull/190
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
Related Vulnerabilities
CVE-2023-30523 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2021-29505 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2012-4387 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2023-35165 Vulnerability in npm package aws-cdk-lib
CVE-2022-24431 Vulnerability in npm package abacus-ext-cmdline