GHSA-6q8v-2hvm-fx37

    Dashboard / Vulnerabilities / GHSA-6q8v-2hvm-fx37

    GHSA-6q8v-2hvm-fx37

    Published: 28 Jun 2022Last Modified: 8 Dec 2024

    Summary: Apache Tika contains incomplete fix for regex DoS

    Details: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

    Affected packages

    Package

    Name: org.apache.tika:tika

    Purl: pkg:maven/org.apache.tika/tika

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.28.4

    Affected versions

    0.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-6q8v-2hvm-fx37 | CVE-DB