ZeroHour

CVE-2021-28657

CVSS 3.1
5.5 medium
EPSS
3%p85
Published
()
Modified
Description

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

Vendors
apacheoracle
Products
tika, healthcare foundation, primavera unifier, webcenter portal, communications messaging server
Weakness
CWE-835
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.