Lucene search

K
osvGoogleOSV:GHSA-6JQ2-789Q-FFF2
HistoryOct 17, 2018 - 3:49 p.m.

High severity vulnerability that affects org.apache.tika:tika-core

2018-10-1715:49:36
Google
osv.dev
14

EPSS

0.003

Percentile

66.1%

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.