Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-30126

Опубликовано: 16 мая 2022
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6tika-coreOut of support scope
Red Hat build of Quarkustika-coreFix deferred
Red Hat Integration Camel K 1tika-coreFix deferred
Red Hat Integration Camel Quarkus 1tika-coreFix deferred
Red Hat JBoss BRMS 5tika-coreOut of support scope
Red Hat JBoss BRMS 6tika-coreOut of support scope
Red Hat JBoss Data Virtualization 6tika-coreOut of support scope
Red Hat JBoss Fuse 6tika-coreOut of support scope
Red Hat JBoss Fuse Service Works 6tika-coreOut of support scope
Red Hat Fuse 7.11tika-coreFixedRHSA-2022:553207.07.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2088523tika-core: Regular Expression Denial of Service in standards extractor

EPSS

Процентиль: 79%
0.01313
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

CVSS3: 5.5
nvd
больше 3 лет назад

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

CVSS3: 5.5
debian
больше 3 лет назад

In Apache Tika, a regular expression in our StandardsText class, used ...

CVSS3: 5.5
github
больше 3 лет назад

Regular expression denial of service in apache tika

EPSS

Процентиль: 79%
0.01313
Низкий

3.1 Low

CVSS3