search cancel

Clarity and CVE-2022-30126

book

Article ID: 243026

calendar_today

Updated On:

Products

Clarity PPM On Premise Clarity PPM SaaS

Issue/Introduction

Clarity 16.0.2 is using tika-core.jar 1.26, is it vulnerable? 

tika-core.jar 1.26 is vulnerable to CVE-2022-30126

CVE-2022-30126 
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

Environment

Release : 16.0.2

Resolution

  • Clarity doesn't use the StandardExtractingContentHandler. We only use tika-core.jar during file upload processing for avatars and personalization images. This vulnerability will not be affecting Clarity.
  • Also, Clarity upgraded to tika-core.jar 2.4.0 in 16.0.3 due in August.