Описание
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Ссылки
- Mailing ListThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Release NotesVendor Advisory
- Mailing ListThird Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Release NotesVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apache Tika before 1.14 allows Java code execution for serialized obje ...
Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2