Thanks to visit codestin.com
Credit goes to github.com

Skip to content

fix CVE-2025-54988 / Tika XXE #3903

@nextgens

Description

@nextgens

The docker deployments should be safe; the containers have no access to internet nor do they have the environment variables...

The same cannot be said of helm deployments.

The fix is in Tika 3.2.2 (apache/tika@bfee6d5); it won't be upgraded to automatically as it requires a change in docker-compose.yml (running setup).

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority/p1(Critical) bug with workaround / Should havetype/securityRelated to security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions