Skip to content

3x-ooxml-bigdecimal-dos#2840

Open
tballison wants to merge 2 commits into
branch_3xfrom
3x-ooxml-bigdecimal-dos
Open

3x-ooxml-bigdecimal-dos#2840
tballison wants to merge 2 commits into
branch_3xfrom
3x-ooxml-bigdecimal-dos

Conversation

@tballison
Copy link
Copy Markdown
Contributor

Thanks for your contribution to Apache Tika! Your help is appreciated!

Before opening the pull request, please verify that

  • there is an open issue on the Tika issue tracker which describes the problem or the improvement. We cannot accept pull requests without an issue because the change wouldn't be listed in the release notes.
  • the issue ID (TIKA-XXXX)
    • is referenced in the title of the pull request
    • and placed in front of your commit messages surrounded by square brackets ([TIKA-XXXX] Issue or pull request title)
  • commits are squashed into a single one (or few commits for larger changes)
  • Tika is successfully built and unit tests pass by running ./mvnw clean test
  • there should be no conflicts when merging the pull request branch into the recent main branch. If there are conflicts, please try to rebase the pull request branch on top of a freshly pulled main branch
  • if you add new module that downstream users will depend upon add it to relevant group in tika-bom/pom.xml.

We will be able to faster integrate your pull request if these conditions are met. If you have any questions how to fix your problem or about using Tika in general, please sign up for the Tika mailing list. Thanks!

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates OOXML custom property extraction to avoid the BigDecimal parsing DoS path by replacing POI/XMLBeans custom-property parsing with a bounded SAX-based parser, plus tests for decimal and text length caps.

Changes:

  • Adds length caps for custom property text and decimal parsing.
  • Parses docProps/custom.xml directly from the OPC package via SAX.
  • Adds unit tests covering capped buffering, oversized decimal rejection, and large string truncation.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
MetadataExtractor.java Replaces XMLBeans custom property extraction with SAX-based extraction and capped decimal handling.
MetadataExtractorTest.java Adds tests for buffer capping and oversized custom-property values.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

public void endElement(String uri, String localName, String qName) {
if (VT_NS.equals(uri) && currentValueType != null &&
localName.equals(currentValueType) && currentPropertyName != null) {
String val = textBuffer.toString().trim();
Comment on lines +304 to +305
case "bool":
customMetadata.set(propName, val);
Comment on lines +276 to +278
} else if (VT_NS.equals(uri) && currentPropertyName != null) {
currentValueType = localName;
textBuffer.setLength(0);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants