Description
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
References (5)
Core 5
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b%40%3Cnotifications.james.apache.org%3E
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210507-0004/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
44.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (12)
apache/tika
< 1.25
oracle/communications_messaging_server
8.1
oracle/healthcare_foundation
7.3.0
oracle/healthcare_foundation
8.0.0
oracle/healthcare_foundation
8.1.0
oracle/primavera_unifier
18.8
oracle/primavera_unifier
19.12
oracle/primavera_unifier
20.12
oracle/primavera_unifier
17.7 - 17.12
oracle/webcenter_portal
12.2.1.3.0
... and 2 more
Published
Mar 31, 2021
Tracked Since
Feb 18, 2026