logo

Database

Insecure deserialization In org.apache.tika:tika-core

Description

Apache Tika allows Java code execution for serialized objects embedded in MATLAB files Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-C7RPH – Vulnerability | Fluid Attacks Database