Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54988

Опубликовано: 20 авг. 2025
Источник: redhat
CVSS3: 9.4
EPSS Низкий

Описание

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

An XML External Entity injection flaw was found in the Apache Tika tika-parser-pdf-module. This vulnerability allows an attacker to provide a crafted XFA file within a PDF, read sensitive data, or trigger malicious requests to internal resources or third-party servers.

Отчет

The tika-parser-pdf-module is used as a test scope dependency during build time in our Camel Spring Boot and JBoss EAP products. However, it is not included in any shipped releases of these products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4tika-parser-pdf-moduleAffected
Red Hat JBoss Enterprise Application Platform 7tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform 8tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packtika-parser-pdf-moduleNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2389910org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA

EPSS

Процентиль: 22%
0.00071
Низкий

9.4 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
8 дней назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 9.8
nvd
8 дней назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 9.8
debian
8 дней назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1. ...

CVSS3: 9.8
github
8 дней назад

Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF

EPSS

Процентиль: 22%
0.00071
Низкий

9.4 Critical

CVSS3