Description
MetadataExtractor 2.1.0 allows stack consumption.
Remediation
References
https://github.com/drewnoakes/metadata-extractor-dotnet/pull/190
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
Related Vulnerabilities
CVE-2021-23337 Vulnerability in maven package org.webjars.bower:lodash
CVE-2022-24815 Vulnerability in npm package generator-jhipster
CVE-2022-36092 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-25898 Vulnerability in maven package org.webjars.npm:jsrsasign
CVE-2022-29251 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui