Description
MetadataExtractor 2.1.0 allows stack consumption.
Remediation
References
https://github.com/drewnoakes/metadata-extractor-dotnet/pull/190
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
Related Vulnerabilities
CVE-2020-26296 Vulnerability in maven package org.webjars.bower:vega
CVE-2023-38889 Vulnerability in maven package org.alluxio:alluxio-core
CVE-2021-26539 Vulnerability in npm package sanitize-html
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2022-31069 Vulnerability in npm package @finastra/nestjs-proxy