cbcvebase.
CVE-2022-33879
published 2022-06-27

CVE-2022-33879: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new…

PriorityP413low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.91%
77.4th percentile
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachetika< 1.28.41.28.4
apachetika
apachetika>= 0 < 1.22-1ubuntu0.1~esm11.22-1ubuntu0.1~esm1
apachetika>= 0 < 1.22-2ubuntu0.22.04.1~esm11.22-2ubuntu0.22.04.1~esm1
apachetika>= 2.0.0 < 2.4.12.4.1
debiantika

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_apache3.3LOW
vendor_oracle3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.