fromTheregister
5 days agoApache warns of 10.0-rated flaw in Tika metadata toolkit
As Apache explained, the entry point for CVE-2025-54988 was Tika's tika-parser-pdf-module, but the vulnerability and its fix were in another piece of code called tika-core. "Users who upgraded the tika-parser-pdf-module but did not upgrade tika-core to >= 3.2.2 would still be vulnerable," the organization advised. The org's new advisory also admits that its original report "failed to mention that in the 1.x Tika releases, the PDFParser was in the org.apache.tika:tika-parsers module." Tika's developers have tidied things up in recent releases, and now users get to revisit this mess too.
Information security









