Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jq2-789q-fff2

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

High severity vulnerability that affects org.apache.tika:tika-core

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

Пакеты

Наименование

org.apache.tika:tika-core

maven
Затронутые версииВерсия исправления

>= 0.1, < 1.19.1

1.19.1

EPSS

Процентиль: 93%
0.11027
Средний

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS3: 7.5
redhat
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS3: 7.5
nvd
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS3: 7.5
debian
больше 7 лет назад

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to lim ...

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость анализатора XML среды обнаружения и анализа контента Apache Tika, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 93%
0.11027
Средний

7.5 High

CVSS3

Дефекты

CWE-611