QID 982685
QID 982685: Java (maven) Security Update for org.apache.tika:tika-core (GHSA-mfwh-gqx8-c787)
A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mfwh-gqx8-c787 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mfwh-gqx8-c787 -
github.com/advisories/GHSA-mfwh-gqx8-c787
CVEs related to QID 982685
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mfwh-gqx8-c787 | org.apache.tika:tika-core |
|