CVE-2022-26336

Vulnerable Component Details
Type Namespace Name Version Package URL
maven org.apache.poi poi 3.17 pkg:maven/org.apache.poi/poi@3.17?type=jar
Vulnerability Details
ID CVE-2022-26336
Description A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
Recommendation . || Upgrade to version 5.2.1 or above.. || Upgrade to version 5.2.1 or above.
Ratings
Severity Score Method Vector Source
5.5 CVSSv31 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H ghsa
4.3 CVSSv2 AV:N/AC:M/Au:N/C:N/I:N/A:P nvd
5.5 CVSSv31 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H nvd
3.5 CVSSv31 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L redhat
Found By Gitlab Gemnasium , Aquasec Trivy
References / Advisories
Weakness Enumeration