CVE-2018-1335
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Productos afectados
Apache Software Foundation · Apache TikaPoCs públicas encontradas — 9
githubgithub.com/SkyBlueEternal/CVE-2018-1335-EXP-GUI★ 14githubgithub.com/canumay/cve-2018-1335★ 1githubgithub.com/siramk/CVE-2018-1335★ 0githubgithub.com/DigitalNinja00/CVE-2018-1335★ 0githubgithub.com/N0b1e6/CVE-2018-1335-Python3★ 0exploitdbwww.exploit-db.com/exploits/46540no verificadocve_referencewww.exploit-db.com/exploits/46540/no verificadoexploitdbwww.exploit-db.com/exploits/47208no verificadocve_referencepacketstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.htmlhttps://access.redhat.com/errata/RHSA-2019:3140https://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca%40%3Cdev.tika.apache.org%3Ehttps://www.exploit-db.com/exploits/46540/http://www.securityfocus.com/bid/104001