QID 981049
QID 981049: Java (maven) Security Update for org.apache.tika:tika-core (GHSA-h8q5-g2cj-qr5h)
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h8q5-g2cj-qr5h for updates pertaining to this vulnerability.
Vendor References
- GHSA-h8q5-g2cj-qr5h -
github.com/advisories/GHSA-h8q5-g2cj-qr5h
CVEs related to QID 981049
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h8q5-g2cj-qr5h | org.apache.tika:tika-core |
|