A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.
References
Configurations
Information
Published : 2019-08-02 12:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-10094
Mitre link : CVE-2019-10094
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
apache
- tika