Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xr4-4c65-hj7f

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Apache Tika does not properly initialize the XML parser or choose handlers

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

Пакеты

Наименование

org.apache.tika:tika-core

maven
Затронутые версииВерсия исправления

< 1.13

1.13

EPSS

Процентиль: 61%
0.00415
Низкий

7.8 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

CVSS3: 5.4
redhat
больше 9 лет назад

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

CVSS3: 7.8
nvd
больше 8 лет назад

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

CVSS3: 7.8
debian
больше 8 лет назад

Apache Tika before 1.13 does not properly initialize the XML parser or ...

EPSS

Процентиль: 61%
0.00415
Низкий

7.8 High

CVSS3

Дефекты

CWE-611