Arbitrary Command Injection Affecting org.apache.tika:tika-server Open this link in a new tab package, versions [,1.18)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
29 Apr 2018
25 Apr 2018
How to fix?
org.apache.tika:tika-server to version 1.18 or higher.
Affected versions of this package are vulnerable to Arbitrary Command Injection. Clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running to the tika-server.