Neal Krawetz

Is CVE-2021-22205 a bug in ExifTool or is it limited to GitLab?

Neal Krawetz

The bug appears to be that GitLab pumps files through ExifTool to remove metadata from JPEG files.
However, if the file is a djvu, then it can run arbitrary code.  (Let me know if I have that wrong.)

In, there is a quoted comment from Phil (2021-04-08?).  If this is fixed, what version of ExifTool contains the fix?


Neal Krawetz

Thank you.

I'm surprised that isn't mentioned in the CVE.
(Glad to know my own use of ExifTool was patched months ago.)