System Exit Vulnerability in Apache Tika's OneNote Parser and Other Parsers
CVE-2020-9489

5.5MEDIUM

Key Information:

Vendor
The Apache
Status
Apache Tika
Vendor
CVE Published:
27 April 2020

Summary

Apache Tika contains vulnerabilities within its OneNote Parser and various other parsers, where a maliciously crafted or corrupt file can lead to unexpected behaviors such as System.exit being invoked. Additionally, these crafted files may cause out of memory errors and infinite loops in several parsers, including ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser, and ImageParser. It is crucial for users to upgrade to version 1.24.1 or later to mitigate these issues. The upgrade also addresses related dependencies, enhancing overall security.

Affected Version(s)

Apache Tika Up to 1.24

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.