← Back to CVE List

CVE-2018-1335

Published: 2018-04-25T21:29Z
Last Modified: 2024-11-21T03:59Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt