Skip to content

[security] T2.1 hardening: cap Tika input stream size (closes 15 CVEs in commons-tika 2.9.x) #92

Description

@natechadwick-intsof

Summary

T2.1 hardening sub-task of parent epic #73. This is defense-in-depth for the 15 CVEs in commons-tika 2.9.x (the latest 1.8-compatible line). The CVEs are in the parser implementations (XML XXE, ZIP-bomb, embedded scripts, SSRF, etc.); closing them requires either a library upgrade (no 1.8-compatible fix available) or defensive code patterns in the few call sites.

This issue covers the 7 production files in the project that use Tika. The hardening is to wrap the input stream with a size cap so that an attacker-controlled file (e.g., a 10 GB uploaded file) is rejected before Tika's parsers see it.

What changes

1. New utility class (1 file, +50)

A small utility that wraps an InputStream with a configurable size cap:

// in PSTikaTextConvertor.getConvertedText(InputStream is, String mimetype):
try (InputStream safe = PSTikaCap.truncate(is, MAX_PARSE_INPUT_BYTES);
     TikaInputStream tis = TikaInputStream.get(safe)) {
    ... // Tika sees a stream that is bounded; if a parser tries to read past the cap,
        // it gets EOF
}

The utility uses a simple byte-counting wrapper that returns EOF after the configured cap is exceeded. Tika handles the EOF gracefully (returns a short parsed result rather than OOM).

2. Apply at the 3 production call sites (3 files)

The 3 files that do full parsing (vs. just mime detection):

File What it does
system/.../PSTikaTextConvertor.java Uses AutoDetectParser to extract text from uploaded files for Lucene indexing. Main attack surface (untrusted file content).
system/services/.../PSDbStorageService.java Uses AutoDetectParser to re-parse metadata from files stored in the DB.
system/services/.../aaclient/PSHashedFileWidgetHandler.java Indirect use; verify the call site.

The 2 files that do only mime detection (AssetsResource.java, PSDbStorageService.java detection half) do not need the size cap — they read only the first few KB to sniff the magic bytes.

The 2 files that are just type definitions (PSMeta.java, PSBinary.java) and the streaming helper (ProxyInputStream.java) do not need changes.

Verification

  • ./mvn-env.sh clean install -DskipTests succeeds on Java 1.8
  • ./mvn-env.sh spotless:check passes
  • A 200 MB file passed to PSTikaTextConvertor.getConvertedText returns a short result (the cap is 100 MB; parser sees EOF at 100 MB) rather than OOM or hanging
  • No UnsupportedClassVersionError in the build log (Tika 2.9.x is Java 8 compatible)

Out of scope (separate issues under #73)

References

Co-Authored by Mavis v1.0.0 using minimax-m3 with agent mavis.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions