CVE-2019-10094: High severity apache tika vulnerability
Published Aug 2, 2019
·Updated
A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.
Affected Software
1 affected component
Apache Tika>=1.7<=1.21
Event History
Aug 2, 2019
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-10094?
CVE-2019-10094 is a vulnerability in Apache Tika that causes a StackOverflowError when unzipping a carefully crafted file that yields the same file (a quine).
2
How do I fix CVE-2019-10094?
To fix CVE-2019-10094, Apache Tika users should upgrade to version 1.22 or later.
3
What is the severity of CVE-2019-10094?
CVE-2019-10094 has a severity of 7.8 (High).