Apache Tika Regular Expression Denial of Service in Standards Extractor
Vulnerability Description
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-30126
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was discovered and reported by the CodeQL team members [@atorralba (Tony Torralba)](https://github.com/atorralba) and [@joefarebrother (Joseph Farebrother)](https://github.com/joefarebrother).
References
- https://lists.apache.org/thread/dh3syg68nxogbmlg13srd6gjn3h2z6r4
- http://www.openwall.com/lists/oss-security/2022/05/16/3
- http://www.openwall.com/lists/oss-security/2022/05/31/2
- http://www.openwall.com/lists/oss-security/2022/06/27/5
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://security.netapp.com/advisory/ntap-20220624-0004/
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.