GHSA-w6g3-v46q-5p28
Dashboard / Vulnerabilities / GHSA-w6g3-v46q-5p28
Summary: Moderate severity vulnerability that affects org.apache.tika:tika-core
Details: In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-11762, https://github.com/advisories/GHSA-w6g3-v46q-5p28, https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b@%3Cdev.tika.apache.org%3E, http://www.securityfocus.com/bid/105515
Affected packages
Package
Name: org.apache.tika:tika-core
Purl: pkg:maven/org.apache.tika/tika-core
Affected ranges
Type: ECOSYSTEM
Events:
