Описание
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Developer Toolset 4.1 | devtoolset-4-tika | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | tika-core | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | tika-parsers | Not affected | ||
| Red Hat Software Collections | rh-eclipse46-tika | Will not fix |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
5.1 Medium
CVSS2
Связанные уязвимости
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apache Tika before 1.14 allows Java code execution for serialized obje ...
Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
7.8 High
CVSS3
5.1 Medium
CVSS2