Adobe Content Authenticity SDK Improper Input Validation Vulnerability Leading to Denial-of-Service
Vulnerability
A denial-of-service vulnerability has been identified in Adobe Content Credentials versions 0.78.2, 0.7.0 and earlier. This issue arises from improper input validation, which could allow an attacker to crash the application, creating a denial-of-service condition. Notably, exploitation of this vulnerability does not require user interaction.
Impact
Exploitation of this vulnerability can cause the application to crash, leading to a denial-of-service condition.
Remediation
Users are advised to update to the latest versions of the Adobe Content Authenticity JS SDK or Rust SDK. The updated version for the JS SDK is @contentauth/c2pa-web@0.7.1, and for the Rust SDK, it is c2pa-v0.80.1.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
