Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1335

Опубликовано: 25 апр. 2018
Источник: debian

Описание

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tikafixed1.18-1package
tikanot-affectedjessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2018/04/25/8

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CVSS3: 8.8
redhat
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CVSS3: 8.1
nvd
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CVSS3: 8.1
github
больше 7 лет назад

Command injection in org.apache.tika:tika-core