MEDIUM 5.9 Maven
Moderate severity vulnerability that affects org.apache.tika:tika-core
GHSA-w6g3-v46q-5p28 · CVE-2018-11762
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Ready to move
Start Securing
Free, no credit card | First findings in minutes