Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccjp-w723-2jf2

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Apache Tika Server exposes sensitive information

Apache Tika provides optional functionality to run itself as a web service to allow remote use. When used in this manner, it's possible for a 3rd party to pass a 'fileUrl' header to the Apache Tika Server (tika-server) before version 1.10. This header lets a remote client request that the server fetches content from the URL provided, including files from the server's local filesystem. Depending on the file permissions set on the local filesystem, this could be used to return sensitive content from the server machine.

This vulnerability only exists if you are running the tika-server version 1.9, and you allow un-trusted access to the tika-server URL. Usage of Apache Tika as a standard library is not affected.

Пакеты

Наименование

org.apache.tika:tika-server

maven
Затронутые версииВерсия исправления

< 1.10

1.10

EPSS

Процентиль: 50%
0.00267
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 9 лет назад

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

CVSS3: 5.3
nvd
около 9 лет назад

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

CVSS3: 5.3
debian
около 9 лет назад

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow re ...

EPSS

Процентиль: 50%
0.00267
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200