VYPR
Low severityNVD Advisory· Published Jun 27, 2022· Updated Aug 3, 2024

Incomplete fix and new regex DoS in StandardsExtractingContentHandler

CVE-2022-33879

Description

The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.tika:tikaMaven
< 1.28.41.28.4
org.apache.tika:tikaMaven
>= 2.0.0, < 2.4.12.4.1

Affected products

4

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.