← back
CVE-2018-11762

CVE-2018-11762

EPSS 5.4%
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 5.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Sep 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →