Multiple Vulnerabilities in Apache Tika - Bloomreach Experience - Open Source CMS

Multiple Vulnerabilities in Apache Tika 

Issue date: 01-11-2019
Affects versions: 13.3, 13.2, 12.6, 11.2

Issue ID: SECURITY-124

 

Affected Product Version(s)
13.3.0, 13.2.2, 12.6.6, 11.2.15.1 (and previous patch releases)


Severity 

Medium


Description

Apache Tika reported vulnerabilities CVE-2019-10088, CVE-2019-10093 and CVE-2019-10094 in versions prior to 1.22.

The Apache Tika dependency has been updated to version 1.22

Instructions

Every customer is advised to upgrade as soon as possible to the latest maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.