QID 980349

QID 980349: Java (maven) Security Update for org.apache.tika:tika (GHSA-567x-m4wm-87v8)

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-567x-m4wm-87v8 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980349

    Software Advisories
    Advisory ID Software Component Link
    GHSA-567x-m4wm-87v8 org.apache.tika:tika URL Logo github.com/advisories/GHSA-567x-m4wm-87v8