CVE-2019-10088: High severity apache tika vulnerability
Published Aug 2, 2019
·Updated
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
Affected Software
1 affected component
Apache Tika>=1.7<=1.21
Remediation
Event History
Aug 2, 2019
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-10088.
2
What is the severity of CVE-2019-10088?
The severity of CVE-2019-10088 is high with a score of 8.8.
3
What is affected by CVE-2019-10088?
Apache Tika versions 1.7-1.21 are affected by CVE-2019-10088.
4
How does CVE-2019-10088 work?
A carefully crafted or corrupt zip file can cause an Out-of-Memory (OOM) error in Apache Tika's RecursiveParserWrapper, leading to a denial of service.
5
How can I mitigate CVE-2019-10088?
Users should upgrade to Apache Tika version 1.22 or later to mitigate CVE-2019-10088.