Input validation error in Apache Tika - CVE-2022-30973

 

Input validation error in Apache Tika - CVE-2022-30973

Published: June 1, 2022


Vulnerability identifier: #VU63904
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30973
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the "StandardsText" class in the StandardsExtractingContentHandler. A remote attacker can trick a victim to open a specially crafted file and perform a denial of service (DoS) attack.


Affected software

Apache Tika
Red Hat Integration Camel-K
IBM Cloud Transformation Advisor
Log Analysis
IBM Cloud Pak for Business Automation
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
Ubuntu
IBM Qradar SIEM
tika (Ubuntu package)
tika-core
IBM FileNet Content Manager

How to mitigate CVE-2022-30973

Install updates from vendor's website.

Apache Tika - addressed in versions 1.28.3, 2.4.0
Red Hat Integration Camel-K - update to 1.8.1
IBM Cloud Transformation Advisor - update to 3.2.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Log Analysis - addressed in versions 1.3.7 FP2, 1.3.7.2 IF001
tika (Ubuntu package) - addressed in versions 1.22-1ubuntu0.1~esm1, 1.22-2ubuntu0.22.04.1~esm1
tika-core - addressed in versions 1.26-150200.3.8.1, 1.26-150300.4.3.1
IBM FileNet Content Manager - addressed in versions 5.5.8.0 IF002, 5.5.9.0 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1

External References

Related Security Bulletins