Apache Tika vulnerabilities

25 known vulnerabilities affecting apache/tika.

Total CVEs
25
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH8MEDIUM14LOW1

Vulnerabilities

Page 2 of 2
CVE-2018-1339MEDIUMCVSS 5.5fixed in 1.182018-04-25
CVE-2018-1339 [MEDIUM] CWE-835 CVE-2018-1339: A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in vers A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
nvd
CVE-2018-1338MEDIUMCVSS 5.5fixed in 1.182018-04-25
CVE-2018-1338 [MEDIUM] CWE-835 CVE-2018-1338: A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in vers A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
nvd
CVE-2016-4434HIGHCVSS 7.8v1.122017-09-30
CVE-2016-4434 [HIGH] CVE-2016-4434: Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.
nvd
CVE-2016-6809CRITICALCVSS 9.8≤ 1.132017-04-06
CVE-2016-6809 [CRITICAL] CWE-502 CVE-2016-6809: Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
nvd
CVE-2015-3271MEDIUMCVSS 5.3v1.92016-12-15
CVE-2015-3271 [MEDIUM] CWE-200 CVE-2015-3271: Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitra Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
nvd