CVE-2022-33879
published 2022-06-27CVE-2022-33879: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new…
PriorityP413low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.91%
77.4th percentile
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | < 1.28.4 | 1.28.4 |
| apache | tika | — | — |
| apache | tika | >= 0 < 1.22-1ubuntu0.1~esm1 | 1.22-1ubuntu0.1~esm1 |
| apache | tika | >= 0 < 1.22-2ubuntu0.22.04.1~esm1 | 1.22-2ubuntu0.22.04.1~esm1 |
| apache | tika | >= 2.0.0 < 2.4.1 | 2.4.1 |
| debian | tika | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_apache3.3LOW
vendor_oracle3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Tika vulnerabilities
vendor_ubuntu·2025-05-23·CVSS 5.5
CVE-2022-30126 [MEDIUM] Apache Tika vulnerabilities
Title: Apache Tika vulnerabilities
Summary: Several security issues were fixed in Apache Tika.
It was discovered that Apache Tika can have an excessive memory usage by
using a crafted or corrupt PSD file. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-1950, CVE-2020-1951)
It was discovered that Apache Tika incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-30126, CVE-2022-30973, CVE-2022-33879)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle HealthCare Applications Risk Matrix: Upload Services (Apache Tika) — CVE-2022-33879
vendor_oracle·2024-07-15·CVSS 3.3
CVE-2022-33879 [LOW] Oracle Oracle HealthCare Applications Risk Matrix: Upload Services (Apache Tika) — CVE-2022-33879
Oracle Oracle HealthCare Applications Risk Matrix: Upload Services (Apache Tika) vulnerability
CVE: CVE-2022-33879
CVSS: 3.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench (Apache Tika) — CVE-2022-33879
vendor_oracle·2024-01-15·CVSS 3.3
CVE-2022-33879 [LOW] Oracle Oracle Commerce Risk Matrix: Workbench (Apache Tika) — CVE-2022-33879
Oracle Oracle Commerce Risk Matrix: Workbench (Apache Tika) vulnerability
CVE: CVE-2022-33879
CVSS: 3.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Tika) — CVE-2022-33879
vendor_oracle·2023-07-15·CVSS 3.3
CVE-2022-33879 [LOW] Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Tika) — CVE-2022-33879
Oracle Oracle Financial Services Applications Risk Matrix: Reports (Apache Tika) vulnerability
CVE: CVE-2022-33879
CVSS: 3.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Document Management (Apache Tika) — CVE-2022-33879
vendor_oracle·2022-10-15·CVSS 3.3
CVE-2022-33879 [LOW] Oracle Oracle Construction and Engineering Risk Matrix: Document Management (Apache Tika) — CVE-2022-33879
Oracle Oracle Construction and Engineering Risk Matrix: Document Management (Apache Tika) vulnerability
CVE: CVE-2022-33879
CVSS: 3.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2022 (OCT 2022)
Debian
CVE-2022-33879: tika - The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the Standa...
vendor_debian·2022·CVSS 5.5
CVE-2022-33879 [MEDIUM] CVE-2022-33879: tika - The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the Standa...
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
Scope: local
bullseye: open
sid: open
Apache
Apache tika: CVE-2022-33879
vendor_apache·CVSS 3.3
CVE-2022-33879 [LOW] Apache tika: CVE-2022-33879
Apache tika: CVE-2022-33879
Regex DoS in StandardsExtractingContentHandler; incomplete fix for
OSV
tika vulnerabilities
osv·2025-05-23·CVSS 5.5
CVE-2020-1950 [MEDIUM] tika vulnerabilities
tika vulnerabilities
It was discovered that Apache Tika can have an excessive memory usage by
using a crafted or corrupt PSD file. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-1950, CVE-2020-1951)
It was discovered that Apache Tika incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-30126, CVE-2022-30973, CVE-2022-33879)
OSV
Apache Tika contains incomplete fix for regex DoS
osv·2022-06-28·CVSS 5.5
CVE-2022-33879 [MEDIUM] Apache Tika contains incomplete fix for regex DoS
Apache Tika contains incomplete fix for regex DoS
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
GHSA
Apache Tika contains incomplete fix for regex DoS
ghsa·2022-06-28·CVSS 5.5
CVE-2022-33879 [MEDIUM] Apache Tika contains incomplete fix for regex DoS
Apache Tika contains incomplete fix for regex DoS
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
OSV
CVE-2022-33879: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate
osv·2022-06-27·CVSS 5.5
CVE-2022-33879 [MEDIUM] CVE-2022-33879: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/06/27/5https://lists.apache.org/thread/wfno8mf5nlcvbs78z93q9thgrm30wwfhhttps://security.netapp.com/advisory/ntap-20220812-0004/http://www.openwall.com/lists/oss-security/2022/06/27/5https://lists.apache.org/thread/wfno8mf5nlcvbs78z93q9thgrm30wwfhhttps://security.netapp.com/advisory/ntap-20220812-0004/
2022-06-27
Published