ID |
CVE-2022-30973
|
Sažetak |
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3. |
Reference |
|
CVSS |
Base: | 2.6 |
Impact: | 2.9 |
Exploitability: | 4.9 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
HIGH |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
NONE |
NONE |
PARTIAL |
|
CVSS vektor |
AV:N/AC:H/Au:N/C:N/I:N/A:P |
Zadnje važnije ažuriranje |
27-10-2022 - 16:41 |
Objavljeno |
31-05-2022 - 14:15 |