QID 981146
QID 981146: Java (maven) Security Update for org.apache.tika:tika-core (GHSA-9r24-gp44-h3pm)
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9r24-gp44-h3pm for updates pertaining to this vulnerability.
Vendor References
- GHSA-9r24-gp44-h3pm -
github.com/advisories/GHSA-9r24-gp44-h3pm
CVEs related to QID 981146
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9r24-gp44-h3pm | org.apache.tika:tika-core |
|