QID 981134
QID 981134: Java (maven) Security Update for org.apache.tika:tika-core (GHSA-ccjp-w723-2jf2)
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ccjp-w723-2jf2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-ccjp-w723-2jf2 -
github.com/advisories/GHSA-ccjp-w723-2jf2
CVEs related to QID 981134
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ccjp-w723-2jf2 | org.apache.tika:tika-core |
|