DoS Vulnerabilities in BPG and CHM Parsers of Apache Tika (CVE-2018-1338, CVE-2018-1339) 

Issue date: 07-05-2018
Affects versions: 12.3, 12.2, 11.2, 10.2


Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 12.3.1, 12.2.2, 11.2.8, and 10.2.12.



A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser or CHMParser in versions before 1.18.
See: CVE-2018-1338CVE-2018-1339

This vulnerability is classified with severity medium, and may (also) apply to project specific usages of the Apache Tika library within a Hippo CMS project. 

The Apache Tika version in all supported CMS maintenance versions 10.2.12, 11.2.8, 12.2.2, and 12.3.1 has been updated to version 1.18.


Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher. This can be done by simply incrementing the version number of the parent POM for the implementation project.