CVE-2022-30126
16.05.2022, 17:15
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0Enginsight
Vendor | Product | Version |
---|---|---|
apache | tika | 𝑥 < 1.28.3 |
apache | tika | 2.0.0 ≤ 𝑥 < 2.4.0 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | primavera_unifier | 20.12 |
oracle | primavera_unifier | 21.12 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References