Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11761

Опубликовано: 19 сент. 2018
Источник: debian
EPSS Средний

Описание

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tikafixed1.20-1package
tikaignoredjessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2018/09/19/4

  • When fixing this issue the fix needs to be made complete to not open

  • CVE-2018-11796. The full fix is only in 1.19.1 onwards.

EPSS

Процентиль: 93%
0.11027
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS3: 7.5
redhat
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS3: 7.5
nvd
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS3: 7.5
github
больше 7 лет назад

High severity vulnerability that affects org.apache.tika:tika-core

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость анализатора XML среды обнаружения и анализа контента Apache Tika, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 93%
0.11027
Средний