ZeroHour

CVE-2022-25169

CVSS 3.1
5.5 medium
EPSS
2%p81
Published
()
Modified
Description

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Vendors
apacheoracle
Products
tika, primavera unifier
Weakness
CWE-770
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.