Inappropriate coding practices In org.apache.tika:tika-parsers
Description
org.apache.tika:tika-parsers has an Infinite Loop vulnerability
Versions of the package org.apache.tika:tika-parsers before version 1.18 are vulnerable to Denial of Service (DoS) via a carefully crafted (or fuzzed) file that can trigger an infinite loop via the ChmParser.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 1.18 | ||
debian 11 | 1.18-1 | ||
maven | 1.18 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2.