Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54988

Опубликовано: 20 авг. 2025
Источник: redhat
CVSS3: 9.4

Описание

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

An XML External Entity injection flaw was found in the Apache Tika tika-parser-pdf-module. This vulnerability allows an attacker to provide a crafted XFA file within a PDF, read sensitive data, or trigger malicious requests to internal resources or third-party servers.

Отчет

Within Red Hat products, the tika-parser-pdf-module is exclusively used for testing purposes at build time, it is not included in any shipped releases of Camel Spring Boot or JBoss EAP.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform 7tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform 8tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packtika-parser-pdf-moduleNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2389910org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA

9.4 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
4 месяца назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 8.4
nvd
4 месяца назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 8.4
debian
4 месяца назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1. ...

CVSS3: 9.8
github
4 месяца назад

Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF

9.4 Critical

CVSS3