Skip to content

Arbitrary code execution in ExifTool

High severity GitHub Reviewed Published May 4, 2021 in photostructure/exiftool-vendored.js • Updated Jan 9, 2023

Package

npm exiftool-vendored (npm)

Affected versions

< 14.3.0

Patched versions

14.3.0

Description

Impact

Arbitrary code execution can occur when running exiftool against files with hostile metadata payloads.

Patches

ExifTool has already been patched in version 12.24. exiftool-vendored, which vendors ExifTool, includes this patch in v14.3.0.

Workarounds

No.

References

https://twitter.com/wcbowling/status/1385803927321415687
https://nvd.nist.gov/vuln/detail/CVE-2021-22204

For more information

If you have any questions or comments about this advisory:

References

Reviewed May 4, 2021
Published to the GitHub Advisory Database May 4, 2021
Last updated Jan 9, 2023

Severity

High
7.8
/ 10

CVSS base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-4whq-r978-2x68

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.