Severity
7.5HIGH
EPSS
11.0%
top 6.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateOct 17

Description

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Mavenorg.apache.tika:tika-core0.11.19.1
NVDapache/tika0.11.18
CVEListV5apache_software_foundation/apache_tika0.1 to 1.18, Apache Tomcat 0.1 to 1.19+1
Debiantika< 1.20-1
NVDoracle/business_process_management_suite12.1.3.0.0, 12.2.1.3.0+1

Patches

🔴Vulnerability Details

5
GHSA
High severity vulnerability that affects org.apache.tika:tika-core2018-10-17
OSV
High severity vulnerability that affects org.apache.tika:tika-core2018-10-17
GHSA
Apache Tika is vulnerable to entity expansions which can lead to a denial of service attack2018-10-17
CVEList
CVE-2018-11761: In Apache Tika 02018-09-19
OSV
CVE-2018-11761: In Apache Tika 02018-09-19

📋Vendor Advisories

4
Red Hat
tika: Incomplete fix allows for XML entity expansion resulting in denial of service2018-10-10
Red Hat
tika: XML entity expansion vulnerability due to lack of limit configuration2018-09-19
Debian
CVE-2018-11761: tika - In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity ...2018
Apache
Apache tika: CVE-2018-11761

💬Community

3
Bugzilla
CVE-2018-11796 tika: Incomplete fix allows for XML entity expansion resulting in denial of service2018-10-15
Bugzilla
CVE-2018-11761 tika: XML entity expansion vulnerability due to lack of limit configuration [fedora-all]2018-09-24
Bugzilla
CVE-2018-11761 tika: XML entity expansion vulnerability due to lack of limit configuration2018-09-24
CVE-2018-11761 (HIGH CVSS 7.5) | In Apache Tika 0.1 to 1.18 | cvebase.io