Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Published 25 Apr 2018Updated 16 Jun 202615 sources
CVSS 8.1 ✓ VERIFIED REFERENCE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.