Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-04-06 14:59
Updated : 2020-08-19 12:17
NVD link : CVE-2016-6809
Mitre link : CVE-2016-6809
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
apache
- nutch
- tika