CVE-2018-11761
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
- Affected products
- Apache Tika
- Apache Tika
- ≤ 1.18
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 8.0% (94th percentile)
- Weakness
- CWE-611
- NVD status
- Modified
- Published
- 2018-09-19
CVE-2018-11761 at NVD
1 known exploit for CVE-2018-11761
Proof-of-concept code and exploit modules indexed by Sploitus