Package
apache-tika-3.3
Component
jetty-http
Latest update
Fixed version
3.3.2-r2
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
3.3.2-r2Status
Previous location
/usr/share/java/tika-server-standard-3.3.1.jarNew location
/usr/share/java/tika-server-standard-3.3.2.jarImpact
version-only path change detected during APK rebuild
Status
Previous location
/usr/share/java/tika-server-standard-3.3.0.jarNew location
/usr/share/java/tika-server-standard-3.3.1.jarImpact
version-only path change detected during APK rebuild
Status
Impact
jetty-http 11.0.28 (the fix for this CVE) is not published to Maven Central. Maven Central's latest 11.0.x release is 11.0.26. Fix gated on upstream apache tika migrating to a supported Jetty branch (12.x).
Status