cbcvebase.

Apache Tika vulnerabilities

25 known vulnerabilities affecting apache/tika.

Total CVEs
25
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH8MEDIUM14LOW1

Vulnerabilities

Page 2 of 2
CVE-2018-1339P4MEDIUMCVSS 5.5fixed in 1.182018-04-25
CVE-2018-1339 [MEDIUM] CWE-835 CVE-2018-1339: A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in vers A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
nvdosv
CVE-2022-30126P4MEDIUMCVSS 5.5fixed in 1.28.3≥ 2.0.0, < 2.4.02022-05-16
CVE-2022-30126 [MEDIUM] CVE-2022-30126: In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingCont In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0
nvd
CVE-2018-1338P4MEDIUMCVSS 5.5fixed in 1.182018-04-25
CVE-2018-1338 [MEDIUM] CWE-835 CVE-2018-1338: A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in vers A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
nvdosv
CVE-2018-8017P4MEDIUMCVSS 5.5≥ 1.2, ≤ 1.182018-09-19
CVE-2018-8017 [MEDIUM] CWE-835 CVE-2018-8017: In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaPar In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
nvdosv
CVE-2022-33879P4LOWCVSS 3.3fixed in 1.28.4≥ 2.0.0, < 2.4.12022-06-27
CVE-2022-33879 [LOW] CVE-2022-33879: The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContent The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
nvd
Apache Tika vulnerabilities | cvebase