REDHAT-BUG-2099553: Low severity apache tika vulnerability
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file.
Reference:
https://www.openwall.com/lists/oss-security/2022/05/31/2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2099553?
The severity of REDHAT-BUG-2099553 is considered high due to the potential for denial of service.
What impact does REDHAT-BUG-2099553 have on users?
REDHAT-BUG-2099553 can lead to a denial of service, affecting the availability of services using Apache Tika.
How do I fix REDHAT-BUG-2099553?
To fix REDHAT-BUG-2099553, upgrade to the latest version of Apache Tika that includes the fix for CVE-2022-30126.
Which versions of Apache Tika are affected by REDHAT-BUG-2099553?
REDHAT-BUG-2099553 affects the 1.x branch, specifically the 1.28.2 release of Apache Tika.
Is there a workaround for REDHAT-BUG-2099553?
No official workaround is recommended for REDHAT-BUG-2099553; upgrading to a patched version is advised.