CVE-2021-28657: Infinite loop in Apache Tika's MP3 parser
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-28657?
CVE-2021-28657 is a vulnerability in Tika's MP3Parser that can be triggered by a carefully crafted or corrupt file, causing an infinite loop.
Which software versions are affected by CVE-2021-28657?
CVE-2021-28657 affects Apache Tika up to and including version 1.25, as well as Oracle Healthcare Foundation versions 7.3.0, 8.0.0, and 8.1.0, Oracle Primavera Unifier versions 17.7 to 17.12, and Oracle WebCenter Portal versions 12.2.1.3.0 and 12.2.1.4.0.
What is the severity of CVE-2021-28657?
CVE-2021-28657 has a severity rating of 5.5, which is considered medium.
How can I fix CVE-2021-28657?
To fix CVE-2021-28657, Apache Tika users should upgrade to version 1.26 or later.
Are there any references for CVE-2021-28657?
Yes, you can find references for CVE-2021-28657 [here](https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b@%3Cnotifications.james.apache.org%3E), [here](https://lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3E), and [here](https://security.netapp.com/advisory/ntap-20210507-0004/).