CVE-2018-1335
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Produtos afetados
Apache Software Foundation · Apache TikaPoCs públicas encontradas — 9
githubgithub.com/SkyBlueEternal/CVE-2018-1335-EXP-GUI★ 14githubgithub.com/canumay/cve-2018-1335★ 1githubgithub.com/siramk/CVE-2018-1335★ 0githubgithub.com/DigitalNinja00/CVE-2018-1335★ 0githubgithub.com/N0b1e6/CVE-2018-1335-Python3★ 0exploitdbwww.exploit-db.com/exploits/46540não verificadocve_referencewww.exploit-db.com/exploits/46540/não verificadoexploitdbwww.exploit-db.com/exploits/47208não verificadocve_referencepacketstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/153864/Apache-Tika-1.17-Header-Command-Injection.htmlhttps://access.redhat.com/errata/RHSA-2019:3140https://lists.apache.org/thread.html/b3ed4432380af767effd4c6f27665cc7b2686acccbefeb9f55851dca%40%3Cdev.tika.apache.org%3Ehttps://www.exploit-db.com/exploits/46540/http://www.securityfocus.com/bid/104001