Lucene search

K
osvGoogleOSV:CVE-2022-30973
HistoryMay 31, 2022 - 2:15 p.m.

CVE-2022-30973

2022-05-3114:15:07
Google
osv.dev
9
apache tika
cve-2022-30126
1.x branch
denial of service
standardsextractingcontenthandler
backtracking
non-standard handler
1.28.3

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

41.5%

We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

41.5%