Severity
5.5MEDIUM
EPSS
0.3%
top 45.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 17

Description

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDapache/tika2.0.02.4.0+1
Mavenorg.apache.tika:tika2.0.02.4.0+1
CVEListV5apache_software_foundation/apache_tikaApache Tika1.28.1
NVDoracle/primavera_unifier17.717.12+4

🔴Vulnerability Details

4
GHSA
Apache Tika vulnerable to uncontrolled memory consumption2022-05-17
OSV
Apache Tika vulnerable to uncontrolled memory consumption2022-05-17
OSV
CVE-2022-25169: The BPG parser in versions of Apache Tika before 12022-05-16
CVEList
Apache Tika BPGParser Memory Usage DoS2022-05-16

📋Vendor Advisories

2
Debian
CVE-2022-25169: tika - The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate a...2022
Apache
Apache tika: CVE-2022-25169
CVE-2022-25169 (MEDIUM CVSS 5.5) | The BPG parser in versions of Apach | cvebase.io