Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6q8v-2hvm-fx37

Опубликовано: 28 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

Apache Tika contains incomplete fix for regex DoS

The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

Пакеты

Наименование

org.apache.tika:tika

maven
Затронутые версииВерсия исправления

< 1.28.4

1.28.4

Наименование

org.apache.tika:tika

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.4.1

2.4.1

EPSS

Процентиль: 8%
0.00031
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 3 лет назад

The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

CVSS3: 3.3
nvd
больше 3 лет назад

The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

CVSS3: 3.3
debian
больше 3 лет назад

The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in ...

EPSS

Процентиль: 8%
0.00031
Низкий

3.3 Low

CVSS3