{"schema_version":"1.9.0","id":"GHSA-567x-m4wm-87v8","published":"2021-05-10T15:23:25Z","modified":"2024-02-17T05:34:30.132120Z","aliases":["CVE-2021-28657"],"summary":"Infinite loop in Apache Tika","details":"A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.","affected":[{"package":{"name":"org.apache.tika:tika","ecosystem":"Maven","purl":"pkg:maven/org.apache.tika/tika"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26"}]}],"versions":["0.2","0.3","1.10","1.11","1.12","1.13","1.14","1.15","1.16","1.17","1.18","1.19","1.19.1","1.20","1.21","1.22","1.23","1.24","1.24.1","1.25","1.6","1.7","1.8","1.9"],"database_specific":{"last_known_affected_version_range":"< 1.25","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-567x-m4wm-87v8/GHSA-567x-m4wm-87v8.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28657"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r4cbc3f6981cd0a1a482531df9d44e4c42a7f63342a7ba78b7bff8a1b@%3Cnotifications.james.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r915add4aa52c60d1b5cf085039cfa73a98d7fae9673374dfd7744b5a%40%3Cdev.tika.apache.org%3E"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210507-0004"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"}],"database_specific":{"cwe_ids":["CWE-400","CWE-835"],"github_reviewed":true,"github_reviewed_at":"2021-04-01T00:18:03Z","nvd_published_at":"2021-03-31T08:15:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}