Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-73263
HistoryJun 01, 2022 - 12:00 a.m.

Apache Tika Denial of Service Vulnerability (CNVD-2022-73263)

2022-06-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

41.6%

Apache Tika is a collection of content extraction tools from the Apache Foundation that integrates POI (an open source library that uses Java programs to provide read and write functionality for Microsoft Office format documents), Pdfbox (a pure Java class library for reading and creating PDF documents) and provides a unified interface for text extraction work. Apache Tika security vulnerability, the vulnerability is due to the regular expression denial of service (ReDoS) flaw in the StandardsExtractingContentHandler in the StandardsText class, a remote attacker can use the vulnerability to cause a denial of service.

CPENameOperatorVersion
apache tikalt1.28.3