CVE-2018-11762: Path Traversal
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11762?
The severity of CVE-2018-11762 is medium, with a severity value of 5.9.
How does CVE-2018-11762 affect Apache Tika?
CVE-2018-11762 affects Apache Tika versions 0.9 to 1.18.
What is the impact of CVE-2018-11762?
The impact of CVE-2018-11762 is that in a rare edge case, tika-app can overwrite a file if the user does not specify an extract directory on the command line and the input file has an embedded file with an absolute path.
How can I fix CVE-2018-11762?
To fix CVE-2018-11762, update Apache Tika to version 1.19 or later.
Where can I find more information about CVE-2018-11762?
You can find more information about CVE-2018-11762 at the following references: [1] http://www.securityfocus.com/bid/105515 [2] https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b@%3Cdev.tika.apache.org%3E