Lucene search

K
cvelistApacheCVELIST:CVE-2022-33879
HistoryJun 27, 2022 - 9:40 p.m.

CVE-2022-33879 Incomplete fix and new regex DoS in StandardsExtractingContentHandler

2022-06-2721:40:10
apache
www.cve.org
1

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%

The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

CNA Affected

[
  {
    "product": "Apache Tika",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "changes": [
          {
            "at": "1.28.4",
            "status": "unaffected"
          }
        ],
        "lessThan": "2.4.1",
        "status": "affected",
        "version": "Apache Tika",
        "versionType": "custom"
      }
    ]
  }
]

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.6%