CVEs (1)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Twelvemonkeys Project 1Twelvemonkeys Nov 21, 2024 May 6, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this...Show more |