CVE-2022-33879
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/06/2022
Last modified:
28/10/2022
Description
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* | 1.28.4 (excluding) | |
| cpe:2.3:a:apache:tika:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.4.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



