Stack Overflow Error in Apache Tika's RecursiveParserWrapper
CVE-2019-10094

7.8HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
2 August 2019

Summary

A specially crafted package or compressed file, when processed by Apache Tika's RecursiveParserWrapper, can trigger a StackOverflowError. This issue affects versions 1.7 through 1.21 of Apache Tika, and it is recommended for all users to upgrade to version 1.22 or later to mitigate this vulnerability. This flaw could lead to resource exhaustion and potential denial-of-service for applications relying on Tika.

Affected Version(s)

Apache Tika 1.7 to 1.21

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.