QID 980816
QID 980816: Java (maven) Security Update for org.apache.tika:tika-core (GHSA-w6g3-v46q-5p28)
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w6g3-v46q-5p28 for updates pertaining to this vulnerability.
Vendor References
- GHSA-w6g3-v46q-5p28 -
github.com/advisories/GHSA-w6g3-v46q-5p28
CVEs related to QID 980816
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w6g3-v46q-5p28 | org.apache.tika:tika-core |
|