Out-Of-Memory Issue in Apache Tika's File Parsing Component
CVE-2019-10088
8.8HIGH
Summary
A vulnerability exists in Apache Tika's RecursiveParserWrapper that allows a specially crafted or corrupt zip file to cause an Out-Of-Memory (OOM) error. This affects versions 1.7 through 1.21 of Apache Tika. To address this security concern, users are highly advised to upgrade to version 1.22 or later to ensure continuous protection from potential exploitation.
Affected Version(s)
Apache Tika 1.7 to 1.21
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved