GHSA-4whq-r978-2x68

    Dashboard / Vulnerabilities / GHSA-4whq-r978-2x68

    GHSA-4whq-r978-2x68

    Published: 4 May 2021Last Modified: 8 Oct 2021

    Summary: Arbitrary code execution in ExifTool

    Details: ### Impact Arbitrary code execution can occur when running `exiftool` against files with hostile metadata payloads. ### Patches ExifTool has already been patched in version 12.24. exiftool-vendored, which vendors ExifTool, includes this patch in v14.3.0. ### Workarounds No. ### References https://twitter.com/wcbowling/status/1385803927321415687 https://nvd.nist.gov/vuln/detail/CVE-2021-22204 ### For more information If you have any questions or comments about this advisory: * Open an issue in [exiftool-vendored](https://github.com/photostructure/exiftool-vendored.js)

    Affected packages

    Package

    Name: exiftool-vendored

    Purl: pkg:npm/exiftool-vendored

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -14.3.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4whq-r978-2x68 | CVE-DB