logo

Database

Asymmetric denial of service - ReDoS In org.apache.tika:tika

Description

Apache Tika contains incomplete fix for regex DoS The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-LBBLD – Vulnerability | Fluid Attacks Database