Описание
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | pre-1.6 |
| esm-apps/xenial | not-affected | pre-1.6 |
| esm-infra-legacy/trusty | DNE | |
| precise | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 1.14 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected | pre-1.6 |
Показывать по
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Apache Tika before 1.14 allows Java code execution for serialized obje ...
Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
7.5 High
CVSS2
9.8 Critical
CVSS3