{"api_version":"1","generated_at":"2026-07-23T11:55:10+00:00","cve":"CVE-2021-23792","urls":{"html":"https://cve.report/CVE-2021-23792","api":"https://cve.report/api/cve/CVE-2021-23792.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-23792","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-23792"},"summary":{"title":"CVE-2021-23792","description":"The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2022-05-06 20:15:00","updated_at":"2022-05-17 17:20:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://snyk.io/vuln/SNYK-JAVA-COMTWELVEMONKEYSIMAGEIO-2316763","name":"N/A","refsource":"CONFIRM","tags":[],"title":"XML External Entity (XXE) Injection in com.twelvemonkeys.imageio:imageio-metadata | CVE-2021-23792 | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/haraldk/TwelveMonkeys/commit/da4efe98bf09e1cce91b7633cb251958a200fc80","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Avoid fetching external resources in XMPReader. · haraldk/TwelveMonkeys@da4efe9 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-23792","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23792","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"MOGWAI LABS GmbH","lang":""},{"source":"LEGACY","value":"Timo Müller","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"23792","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"twelvemonkeys_project","cpe5":"twelvemonkeys","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-23792","qid":"182511","title":"Debian Security Update for libtwelvemonkeys-java (CVE-2021-23792)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"report@snyk.io","DATE_PUBLIC":"2022-05-06T20:00:10.594529Z","ID":"CVE-2021-23792","STATE":"PUBLIC","TITLE":"XML External Entity (XXE) Injection"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"com.twelvemonkeys.imageio:imageio-metadata","version":{"version_data":[{"version_affected":"<","version_value":"3.7.1"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"XML External Entity (XXE) Injection"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-JAVA-COMTWELVEMONKEYSIMAGEIO-2316763","name":"https://snyk.io/vuln/SNYK-JAVA-COMTWELVEMONKEYSIMAGEIO-2316763"},{"refsource":"MISC","url":"https://github.com/haraldk/TwelveMonkeys/commit/da4efe98bf09e1cce91b7633cb251958a200fc80","name":"https://github.com/haraldk/TwelveMonkeys/commit/da4efe98bf09e1cce91b7633cb251958a200fc80"}]},"description":{"description_data":[{"lang":"eng","value":"The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered."}]},"impact":{"cvss":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},"credit":[{"lang":"eng","value":"MOGWAI LABS GmbH"},{"lang":"eng","value":"Timo Müller"}]},"nvd":{"publishedDate":"2022-05-06 20:15:00","lastModifiedDate":"2022-05-17 17:20:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:twelvemonkeys_project:twelvemonkeys:*:*:*:*:*:*:*:*","versionEndExcluding":"3.7.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"23792","Ordinal":"198519","Title":"CVE-2021-23792","CVE":"CVE-2021-23792","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"23792","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}