Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35785
HistoryJun 01, 2022 - 10:24 a.m.

Regular Expression Denial Of Service (ReDoS)

2022-06-0110:24:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.001 Low

EPSS

Percentile

41.6%

org.apache.tika:tika is vulnerable to regular expression denial of service (ReDoS) attacks. An attacker is able to cause denial of service conditions to the users who are running the StandardsExtractingContentHandler, due to a insecure regular expression usage in StandardsText class by backtracking on a specially crafted file. This resolves an incomplete fix for the 1.x branch in CVE-2022-30126.