CVE-2018-1335
82Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 94%
de la publicación al arma322 días
Publicada en NVD25 abr
1ª PoC+322d
metasploit25 abr
VulnCheck+2050d
probabilidad de explotación
94%top 1% de las CVE
explotación observada
síVulnCheck
14 exploit(s) público(s)
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Productos afectados
Apache Software Foundation · Apache TikaPoCs públicas encontradas — 14✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46540exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47208githubgithub.com/SkyBlueEternal/CVE-2018-1335-EXP-GUI★ 14githubgithub.com/canumay/cve-2018-1335★ 1githubgithub.com/siramk/CVE-2018-1335★ 0githubgithub.com/DigitalNinja00/CVE-2018-1335★ 0githubgithub.com/N0b1e6/CVE-2018-1335-Python3★ 0vulncheckvulncheck.com/xdb/509c75796be5no verificadovulncheckvulncheck.com/xdb/c9ddc2b4526eno verificadocve_referencewww.exploit-db.com/exploits/46540/no verificadocve_referencepacketstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.htmlno verificadovulncheckvulncheck.com/xdb/03afb5c3d4bdno verificadovulncheckvulncheck.com/xdb/147026ce3d31no verificadovulncheckvulncheck.com/xdb/8c09b09421aeno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.htmlhttps://access.redhat.com/errata/RHSA-2019:3140https://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca%40%3Cdev.tika.apache.org%3Ehttps://www.exploit-db.com/exploits/46540/http://www.securityfocus.com/bid/104001