Lucene search

K
cvelistApacheCVELIST:CVE-2022-30126
HistoryMay 16, 2022 - 5:05 p.m.

CVE-2022-30126 Apache Tika Regular Expression Denial of Service in Standards Extractor

2022-05-1617:05:13
apache
www.cve.org
6
apache tika
regular expression
denial of service
standards extractor
cve-2022-30126
1.28.2
2.4.0

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

39.4%

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

CNA Affected

[
  {
    "product": "Apache Tika",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "1.28.1",
        "status": "affected",
        "version": "Apache Tika",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

39.4%