QID 982686

QID 982686: Java (maven) Security Update for org.apache.tika:tika-parsers (GHSA-4mq5-mj59-qq9c)

In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-4mq5-mj59-qq9c for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982686

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4mq5-mj59-qq9c org.apache.tika:tika-parsers URL Logo github.com/advisories/GHSA-4mq5-mj59-qq9c