CVE-2016-4434
published 2017-09-30CVE-2016-4434: Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE)…
PriorityP342high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
3.45%
87.7th percentile
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | — | — |
| apache | tika | >= 0 < 1.18-1 | 1.18-1 |
| debian | tika | < tika 1.18-1 (bullseye) | tika 1.18-1 (bullseye) |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa7.8HIGH
osv7.8HIGH
vendor_apache7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Tika does not properly initialize the XML parser or choose handlers
osv·2018-10-17·CVSS 7.8
CVE-2016-4434 [HIGH] Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
GHSA
Apache Tika does not properly initialize the XML parser or choose handlers
ghsa·2018-10-17·CVSS 7.8
CVE-2016-4434 [HIGH] CWE-611 Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika does not properly initialize the XML parser or choose handlers
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
OSV
CVE-2016-4434: Apache Tika before 1
osv·2017-09-30·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434: Apache Tika before 1
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
Red Hat
tika: XML External Entity vulnerability
vendor_redhat·2016-05-26·CVSS 7.8
CVE-2016-4434 [HIGH] CWE-611 tika: XML External Entity vulnerability
tika: XML External Entity vulnerability
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
It was found that the parsing of OOXML, XMP in PDF, and some other file formats by Apache Tika would expand entity references. A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: tika-core (Red Hat BPM Suite 6) - Affected
Package: tika-core (Red Hat JBoss BRMS 5) - Will not fix
Package: tika-core (Red Hat JB
Debian
CVE-2016-4434: tika - Apache Tika before 1.13 does not properly initialize the XML parser or choose ha...
vendor_debian·2016·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434: tika - Apache Tika before 1.13 does not properly initialize the XML parser or choose ha...
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
Scope: local
bullseye: resolved (fixed in 1.18-1)
sid: resolved (fixed in 1.18-1)
Apache
Apache tika: CVE-2016-4434
vendor_apache·CVSS 7.8
CVE-2016-4434 [HIGH] Apache tika: CVE-2016-4434
Apache tika: CVE-2016-4434
XXE Vulnerability in several parsers Arthur Khashaev, Seulgi Kim, Mesut Timur (and Tim Allison while remediating initial issue reported by Arthur et al.) 0.10-1.12
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4434 tika: XML External Entity vulnerability [fedora-all]
bugzilla·2016-05-27·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434 tika: XML External Entity vulnerability [fedora-all]
CVE-2016-4434 tika: XML External Entity vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2016-4434 tika: XML External Entity vulnerability
bugzilla·2016-05-27·CVSS 7.8
CVE-2016-4434 [HIGH] CVE-2016-4434 tika: XML External Entity vulnerability
CVE-2016-4434 tika: XML External Entity vulnerability
Apache Tika parses XML within numerous file formats. In some instances, such as spreadsheets in OOXML files, XMP in PDF, and other file formats, the initialization of the XML parser or the choice of handlers did not protect against XML External Entity (XXE) vulnerabilities.
References:
http://seclists.org/oss-sec/2016/q2/413
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1340387]
---
This issue has been addressed in the following products:
Red Hat JBoss BPM Suite 6.4.1
Via RHSA-2017:0249 https://rhn.redhat.com/errata/RHSA-2017-0249.html
---
This issue has been addressed in the following products:
Red Hat JBoss BRMS 6.4.1
Via RHSA-2017:0248 https://rhn.redhat.com/errata/RHSA-2017-0248.html
http://rhn.redhat.com/errata/RHSA-2017-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0249.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0272.htmlhttp://www.securityfocus.com/archive/1/538500/100/0/threadedhttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://mail-archives.apache.org/mod_mbox/tika-dev/201605.mbox/%3C1705136517.1175366.1464278135251.JavaMail.yahoo%40mail.yahoo.com%3Ehttp://rhn.redhat.com/errata/RHSA-2017-0248.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0249.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0272.htmlhttp://www.securityfocus.com/archive/1/538500/100/0/threadedhttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://mail-archives.apache.org/mod_mbox/tika-dev/201605.mbox/%3C1705136517.1175366.1464278135251.JavaMail.yahoo%40mail.yahoo.com%3E
2017-09-30
Published