CVE-2015-3271
published 2016-12-15CVE-2015-3271: Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
PriorityP338medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
6.52%
93.0th percentile
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | — | — |
| debian | tika | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache5.3MEDIUM
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-3271: tika - Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attac...
vendor_debian·2015·CVSS 5.3
CVE-2015-3271 [MEDIUM] CVE-2015-3271: tika - Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attac...
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
Scope: local
bullseye: resolved
sid: resolved
Apache
Apache tika: CVE-2015-3271
vendor_apache·CVSS 5.3
CVE-2015-3271 [MEDIUM] Apache tika: CVE-2015-3271
Apache tika: CVE-2015-3271
Remote Access to host files via tika-server Tim Allison 1.9?-1.10 PDFBOX-2811 Apache PDFBox - Infinite Loop Andreas Lehmkühler ?-1.10 PDFBOX-2200 Apache PDFBox - Slowly building memory leak because of static caching of fonts Matthew Buckett ?-1.6 TIKA-1471 Apache PDFBox - OOM with corrupt PDF Alan Burlison ?-1.6 TIKA-788 Infinite Loop in DWG Stas Shaposhnikov ?-1.4? TIKA-1132 Apache POI - Nearly Infinite Loop in XLS Ryan Krueger ?-1.4 TIKA-1179 Infinite Loop in corrupt MP3 Marius Dumitru Florea ?-1.4 TIKA-866 OOM reading Tika config file Stephan Mühlstrasser ?-1.1 Third party vulnerabilities that may or may not be triggerable via regular use of Apache Tika. CVE or Vulnerability Description Reporter Affected Versions
OSV
Apache Tika Server exposes sensitive information
osv·2018-10-17
CVE-2015-3271 [MEDIUM] Apache Tika Server exposes sensitive information
Apache Tika Server exposes sensitive information
Apache Tika provides optional functionality to run itself as a web service to allow remote use. When used in this manner,
it's possible for a 3rd party to pass a 'fileUrl' header to the Apache Tika Server (tika-server) before version 1.10. This header lets a remote client request that the server fetches content from the URL provided, including files from the server's local filesystem. Depending on the file permissions set on the local filesystem, this could be used to return sensitive content from the server machine.
This vulnerability only exists if you are running the tika-server version 1.9, and you allow un-trusted access to the tika-server
URL. Usage of Apache Tika as a standard library is not affected.
GHSA
Apache Tika Server exposes sensitive information
ghsa·2018-10-17
CVE-2015-3271 [MEDIUM] CWE-200 Apache Tika Server exposes sensitive information
Apache Tika Server exposes sensitive information
Apache Tika provides optional functionality to run itself as a web service to allow remote use. When used in this manner,
it's possible for a 3rd party to pass a 'fileUrl' header to the Apache Tika Server (tika-server) before version 1.10. This header lets a remote client request that the server fetches content from the URL provided, including files from the server's local filesystem. Depending on the file permissions set on the local filesystem, this could be used to return sensitive content from the server machine.
This vulnerability only exists if you are running the tika-server version 1.9, and you allow un-trusted access to the tika-server
URL. Usage of Apache Tika as a standard library is not affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3271 tika: Information disclosure vulnerability when running Apache Tika Server [fedora-all]
bugzilla·2015-08-25·CVSS 5.3
CVE-2015-3271 [MEDIUM] CVE-2015-3271 tika: Information disclosure vulnerability when running Apache Tika Server [fedora-all]
CVE-2015-3271 tika: Information disclosure vulnerability when running Apache Tika Server [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2015-3271 tika: Information disclosure vulnerability when running Apache Tika Server
bugzilla·2015-08-25·CVSS 5.3
CVE-2015-3271 [MEDIUM] CVE-2015-3271 tika: Information disclosure vulnerability when running Apache Tika Server
CVE-2015-3271 tika: Information disclosure vulnerability when running Apache Tika Server
Apache Tika provides optional functionality to run itself as a web service to allow remote use. When used in this
manner, it's possible for a 3rd party to pass a 'fileUrl' header to the Apache Tika Server (tika-server).
This header lets a remote client request that the server fetches content from the URL provided, including files
from the server's local filesystem.
Depending on the file permissions set on the local filesystem, this could be used to return sensitive content from
the server machine.
This vulnerability only exists if you are running the tika-server version 1.9, and you allow un-trusted access
to the tika-server URL. Usage of Apache Tika as a standard library is not affected.
Mitigation
http://www.openwall.com/lists/oss-security/2015/08/13/5http://www.securityfocus.com/bid/95020https://lists.apache.org/thread.html/d2b3e7afb0251fac95fdee9817423cbc91e3d99a848c25a51d91c1e8%401439485507%40%3Cdev.tika.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2015/08/13/5http://www.securityfocus.com/bid/95020https://lists.apache.org/thread.html/d2b3e7afb0251fac95fdee9817423cbc91e3d99a848c25a51d91c1e8%401439485507%40%3Cdev.tika.apache.org%3E
2016-12-15
Published