System Exit Vulnerability in Apache Tika's OneNote Parser and Other Parsers
CVE-2020-9489
What is CVE-2020-9489?
Apache Tika contains vulnerabilities within its OneNote Parser and various other parsers, where a maliciously crafted or corrupt file can lead to unexpected behaviors such as System.exit being invoked. Additionally, these crafted files may cause out of memory errors and infinite loops in several parsers, including ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser, and ImageParser. It is crucial for users to upgrade to version 1.24.1 or later to mitigate these issues. The upgrade also addresses related dependencies, enhancing overall security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Tika Up to 1.24
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
