First published: Fri Aug 02 2019(Updated: )
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tika | >=1.19<=1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10093 is a vulnerability in Apache Tika 1.19 to 1.21 that allows a carefully crafted 2003ml or 2006ml file to consume all available SAXParsers in the pool, leading to long hangs.
CVE-2019-10093 has a severity rating of 6.5 (medium).
To fix CVE-2019-10093, Apache Tika users should upgrade to version 1.22 or later.
Apache Tika versions 1.19 to 1.21 are affected by CVE-2019-10093.
The Common Weakness Enumeration (CWE) number for CVE-2019-10093 is 770.