CVE-2019-10093
published 2019-08-02CVE-2019-10093: In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache…
PriorityP431medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.70%
88.4th percentile
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_tika | — | — |
| apache | tika | — | — |
| apache | tika | >= 0 < 1.22-1 | 1.22-1 |
| apache | tika | 1.19 – 1.21 | — |
| debian | tika | < tika 1.22-1 (bullseye) | tika 1.22-1 (bullseye) |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_apache6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Allocation of Resources Without Limits or Throttling in Apache Tika
ghsa·2019-08-06
CVE-2019-10093 [MEDIUM] CWE-770 Allocation of Resources Without Limits or Throttling in Apache Tika
Allocation of Resources Without Limits or Throttling in Apache Tika
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
OSV
Allocation of Resources Without Limits or Throttling in Apache Tika
osv·2019-08-06
CVE-2019-10093 [MEDIUM] Allocation of Resources Without Limits or Throttling in Apache Tika
Allocation of Resources Without Limits or Throttling in Apache Tika
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
OSV
CVE-2019-10093: In Apache Tika 1
osv·2019-08-02·CVSS 6.5
CVE-2019-10093 [MEDIUM] CVE-2019-10093: In Apache Tika 1
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
Debian
CVE-2019-10093: tika - In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could con...
vendor_debian·2019·CVSS 6.5
CVE-2019-10093 [MEDIUM] CVE-2019-10093: tika - In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could con...
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
Scope: local
bullseye: resolved (fixed in 1.22-1)
sid: resolved (fixed in 1.22-1)
Apache
Apache tika: CVE-2019-10093
vendor_apache·CVSS 6.5
CVE-2019-10093 [MEDIUM] Apache tika: CVE-2019-10093
Apache tika: CVE-2019-10093
Denial of Service in Apache Tika's 2003ml and 2006ml Parsers Tim Allison 1.19-1.21
No detection rules found.
No public exploits indexed.
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
Bugzilla
CVE-2019-10093 tika: arefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to DoS
bugzilla·2019-12-02·CVSS 6.5
CVE-2019-10093 [MEDIUM] CVE-2019-10093 tika: arefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to DoS
CVE-2019-10093 tika: arefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to DoS
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
External References:
https://lists.apache.org/thread.html/a5a44eff1b9eda3bc69d22943a1030c43d376380c75d3ab04d0c1a21@%3Cdev.tika.apache.org%3E
https://lists.apache.org/thread.html/39723d8227b248781898c200aa24b154683673287b150a204b83787d%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/a5a44eff1b9eda3bc69d22943a1030c43d376380c75d3ab04d0c1a21%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/da9ee189d1756f8508d0f2386d8e25aca5a6df541739829232be8a94%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/fb6c84fd387de997e5e366d50b0ca331a328c466432c80f8c5eed33d%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190828-0004/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://lists.apache.org/thread.html/39723d8227b248781898c200aa24b154683673287b150a204b83787d%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/a5a44eff1b9eda3bc69d22943a1030c43d376380c75d3ab04d0c1a21%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/da9ee189d1756f8508d0f2386d8e25aca5a6df541739829232be8a94%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/fb6c84fd387de997e5e366d50b0ca331a328c466432c80f8c5eed33d%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190828-0004/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.html
2019-08-02
Published