CVE-2021-28657

Severity
5.5MEDIUM
EPSS
0.2%
top 55.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateApr 15

Description

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

Mavenorg.apache.tika:tika< 1.26
CVEListV5apache_software_foundation/apache_tikaApache Tika1.26
NVDapache/tika1.25
NVDoracle/primavera_unifier17.717.12+3
NVDoracle/webcenter_portal12.2.1.3.0, 12.2.1.4.0+1

Patches

🔴Vulnerability Details

4
OSV
Infinite loop in Apache Tika2021-05-10
GHSA
Infinite loop in Apache Tika2021-05-10
CVEList
Infinite loop in Apache Tika's MP3 parser2021-03-31
OSV
CVE-2021-28657: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 12021-03-31

📋Vendor Advisories

5
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Apache Tika) — CVE-2021-286572022-04-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Monitoring (Apache Tika) — CVE-2021-286572021-10-15
Red Hat
tika-parsers: Infinite loop in MP3Parser2021-03-30
Debian
CVE-2021-28657: tika - A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Pa...2021
Apache
Apache tika: CVE-2021-28657
CVE-2021-28657 (MEDIUM CVSS 5.5) | A carefully crafted or corrupt file | cvebase.io