Adobe CAI Content Credentials Rust SDK
- <c2pa-v0.84.0
A vulnerability in Adobe Content Credentials has been identified, stemming from improper input validation. This issue could allow an attacker to read arbitrary files from the file system, accessing sensitive information and directories beyond the intended access scope. Exploitation requires user interaction, as a victim must open a malicious file. The vulnerability affects multiple components of the Content Credentials SDK, including the Rust SDK, Command-Line Tool, and JS SDK, all prior to specific updated versions.
Exploitation of this vulnerability could result in unauthorized access to sensitive files and directories, allowing attackers to read information outside of the intended access scope.
Users are advised to update to the latest version of the Adobe Content Credentials SDK. The updated versions are available on the Adobe website and through the Adobe Update mechanism.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.