CVE-2021-28657
published 2021-03-31CVE-2021-28657: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.75%
84.6th percentile
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | <= 1.25 | — |
| apache | tika | — | — |
| apache_software_foundation | apache_tika | >= Apache Tika < 1.26 | 1.26 |
| debian | tika | — | — |
| oracle | communications_messaging_server | — | — |
| oracle | healthcare_foundation | — | — |
| oracle | healthcare_foundation | — | — |
| oracle | healthcare_foundation | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | 17.7 – 17.12 | — |
| oracle | webcenter_portal | — | — |
| oracle | webcenter_portal | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_apache5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Tika) — CVE-2021-28657
vendor_oracle·2022-04-15·CVSS 5.5
CVE-2021-28657 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Tika) — CVE-2021-28657
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Tika) vulnerability
CVE: CVE-2021-28657
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache Tika) — CVE-2021-28657
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2021-28657 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache Tika) — CVE-2021-28657
Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache Tika) vulnerability
CVE: CVE-2021-28657
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Red Hat
tika-parsers: Infinite loop in MP3Parser
vendor_redhat·2021-03-30·CVSS 5.5
CVE-2021-28657 [MEDIUM] CWE-835 tika-parsers: Infinite loop in MP3Parser
tika-parsers: Infinite loop in MP3Parser
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
Package: tika-parsers (Red Hat BPM Suite 6) - Out of support scope
Package: tika-parsers (Red Hat Fuse 7) - Fix deferred
Package: tika-parsers (Red Hat Integration Camel K 1) - Fix deferred
Package: tika-parsers (Red Hat Integration Camel Quarkus 1) - Fix deferred
Package: tika-parsers (Red Hat JBoss BRMS 5) - Out of support scope
Package: tika-parsers (Red Hat JBoss BRMS 6) - Out of support scope
Package: tika-parsers (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: tika-parsers (Red Hat JBoss Fuse 6) - Out of support scope
Package: tika-parsers (Red Hat
Debian
CVE-2021-28657: tika - A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Pa...
vendor_debian·2021·CVSS 5.5
CVE-2021-28657 [MEDIUM] CVE-2021-28657: tika - A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Pa...
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
Scope: local
bullseye: open
sid: open
Apache
Apache tika: CVE-2021-28657
vendor_apache·CVSS 5.5
CVE-2021-28657 [MEDIUM] Apache tika: CVE-2021-28657
Apache tika: CVE-2021-28657
Infinite loop in the MP3Parser. Khaled Nassar ?-1.25
OSV
Infinite loop in Apache Tika
osv·2021-05-10
CVE-2021-28657 [MEDIUM] Infinite loop in Apache Tika
Infinite loop in Apache Tika
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
GHSA
Infinite loop in Apache Tika
ghsa·2021-05-10
CVE-2021-28657 [MEDIUM] CWE-400 Infinite loop in Apache Tika
Infinite loop in Apache Tika
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
OSV
CVE-2021-28657: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1
osv·2021-03-31·CVSS 5.5
CVE-2021-28657 [MEDIUM] CVE-2021-28657: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b%40%3Cnotifications.james.apache.org%3Ehttps://lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210507-0004/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b%40%3Cnotifications.james.apache.org%3Ehttps://lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210507-0004/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-31
Published