The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
2022-06-27T22:15:09.377
2024-11-21T07:08:30.923
Modified
CVSSv3.1: 3.3 (LOW)
AV:N/AC:H/Au:N/C:N/I:N/A:P
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | tika | < 1.28.4 | Yes |
Application | apache | tika | < 2.4.1 | Yes |