Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r24-gp44-h3pm

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Command injection in org.apache.tika:tika-core

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Пакеты

Наименование

org.apache.tika:tika-core

maven
Затронутые версииВерсия исправления

>= 1.7, < 1.18

1.18

EPSS

Процентиль: 100%
0.93644
Критический

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CVSS3: 8.8
redhat
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CVSS3: 8.1
nvd
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

CVSS3: 8.1
debian
почти 8 лет назад

From Apache Tika versions 1.7 to 1.17, clients could send carefully cr ...

EPSS

Процентиль: 100%
0.93644
Критический

8.1 High

CVSS3