Description
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Upgrade to 1.28.2 or 2.4.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5214 | In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0 |
Github GHSA |
GHSA-rpjm-422r-95mh | Regular expression denial of service in apache tika |
Ubuntu USN |
USN-7529-1 | Apache Tika vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T06:40:47.590Z
Reserved: 2022-05-03T00:00:00.000Z
Link: CVE-2022-30126
No data.
Status : Modified
Published: 2022-05-16T17:15:09.640
Modified: 2024-11-21T07:02:12.520
Link: CVE-2022-30126
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN