← Back

CVE-2021-28657

nvd nist
Published: Mar 31, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

Affected (11)

1 product
Tika
4 products
Communications Messaging Server
Healthcare Foundation
Primavera Unifier
Webcenter Portal
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.25
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.1
Oracle
Version 7.3.0
Version 8.0.0
Version 8.1.0
Oracle
From 17.7 to 17.12
Version 18.8
Version 19.12
Version 20.12
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0

References (10)

Timeline

No history available yet.