CVE-2019-10093

EUVD-2019-0618
In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
apachetika
1.19 ≤
𝑥
≤ 1.21
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tika
bullseye
1.22-2
fixed
buster
no-dsa
jessie
not-affected
sid
1.22-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tika
bionic
not-affected
disco
ignored
eoan
Fixed 1.22-1
released
trusty
dne
xenial
not-affected
References