Apache Tika contains incomplete fix for regex DoS
Low severity
GitHub Reviewed
Published
Jun 28, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
< 1.28.4
>= 2.0.0, < 2.4.1
Patched versions
1.28.4
2.4.1
Description
Published by the National Vulnerability Database
Jun 27, 2022
Published to the GitHub Advisory Database
Jun 28, 2022
Reviewed
Jul 8, 2022
Last updated
Jan 27, 2023
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
References