CVE-2021-28657 Vulnerability Details

  /     /     /  

CVE-2021-28657 Metadata Quick Info

CVE Published: 31/03/2021 | CVE Updated: 03/08/2024 | CVE Year: 2021
Source: apache | Vendor: Apache Software Foundation | Product: Apache Tika
Status : PUBLISHED

CVE-2021-28657 Description

A carefully crafted or corrupt file may trigger an infinite loop in Tika\'s MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-835
CWE Name: CWE-835 Infinite Loop
Source: Apache Software Foundation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).