CVE-2022-26336 – org.apache.poi:poi-scratchpad
Package
Manager: maven
Name: org.apache.poi:poi-scratchpad
Vulnerable Version: >=3.8-beta1 <5.2.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00046 pctl0.1352
Details
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
Metadata
Created: 2022-03-05T00:00:44Z
Modified: 2024-05-15T06:54:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-mqvp-7rrg-9jxc/GHSA-mqvp-7rrg-9jxc.json
CWE IDs: ["CWE-20", "CWE-770"]
Alternative ID: GHSA-mqvp-7rrg-9jxc
Finding: F067
Auto approve: 1