Security Advisory

CVE-2022-30126

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-05-16 17:05:13
Last updated 2024-08-03 06:40:47
Assigner apache
State PUBLISHED

Description

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0