CVE-2019-10094

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/08/2019
Last modified:
07/11/2023

Description

A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* 1.7 (including) 1.21 (including)