CVE-2019-10094

CVSS v3.0 7.8 (High)
78% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.19 % (56th)
0.19% Progress
Affected Products 1
Advisories 3

A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.

Weaknesses
CWE-770
Allocation of Resources Without Limits or Throttling
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2019-08-02 19:15:11
(5 years ago)
Updated Date
2023-11-07 03:02:23
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Tika from 1.7 version and 1.21 and prior versions cpe:2.3:a:apache:tika >= 1.7 <= 1.21
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...