Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54988

Опубликовано: 20 авг. 2025
Источник: redhat
CVSS3: 9.4
EPSS Низкий

Описание

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

An XML External Entity injection flaw was found in the Apache Tika tika-parser-pdf-module. This vulnerability allows an attacker to provide a crafted XFA file within a PDF, read sensitive data, or trigger malicious requests to internal resources or third-party servers.

Отчет

Within Red Hat products, the tika-parser-pdf-module is exclusively used for testing purposes at build time, it is not included in any shipped releases of Camel Spring Boot or JBoss EAP.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform 7tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform 8tika-parser-pdf-moduleNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packtika-parser-pdf-moduleNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2389910org.apache.tika/tika-parser-pdf-module: Apache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA

EPSS

Процентиль: 5%
0.00023
Низкий

9.4 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
6 месяцев назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 8.4
nvd
6 месяцев назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a dependency in several Tika packages including at least: tika-parsers-standard-modules, tika-parsers-standard-package, tika-app, tika-grpc and tika-server-standard. Users are recommended to upgrade to version 3.2.2, which fixes this issue.

CVSS3: 8.4
debian
6 месяцев назад

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1. ...

CVSS3: 9.8
github
6 месяцев назад

Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF

CVSS3: 9.8
fstec
6 месяцев назад

Уязвимость модулей tika-core, tika-pdf-module и tika-parsers среды обнаружения и анализа контента Apache Tika, позволяющая нарушителю проводить XXE-атаки

EPSS

Процентиль: 5%
0.00023
Низкий

9.4 Critical

CVSS3