PT-2019-4680 · Apache+1 · Apache Tika+1
Published
2019-08-02
·
Updated
2020-08-24
·
CVE-2019-10093
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Tika versions 1.19 through 1.21
Description
The issue is related to an uncontrolled resource consumption in Apache Tika. A carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool, leading to very long hangs. This could allow a remote attacker to cause a denial of service.
Recommendations
For Apache Tika versions 1.19 through 1.21, upgrade to version 1.22 or later to resolve the issue.
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tika
Suse