Описание
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | tika-core | Out of support scope | ||
| Red Hat build of Quarkus | tika-core | Not affected | ||
| Red Hat Fuse 7 | tika-core | Fix deferred | ||
| Red Hat Integration Camel Quarkus 1 | tika-core | Fix deferred | ||
| Red Hat JBoss BRMS 5 | tika-core | Out of support scope | ||
| Red Hat JBoss BRMS 6 | tika-core | Out of support scope | ||
| Red Hat JBoss Data Virtualization 6 | tika-core | Out of support scope | ||
| Red Hat JBoss Fuse 6 | tika-core | Out of support scope | ||
| Red Hat JBoss Fuse Service Works 6 | tika-core | Out of support scope | ||
| RHINT Camel-K 1.8.1 | tika-core | Fixed | RHSA-2022:7257 | 27.10.2022 |
Показывать по
Дополнительная информация
Статус:
3.1 Low
CVSS3
Связанные уязвимости
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the ...
Regular expression denial of service in apache tika
3.1 Low
CVSS3