CyberRota Analysis
AI-GeneratedThe Apache Tika ISA-Tab parser is vulnerable to a relative path traversal exploit, allowing attackers to read arbitrary files accessible to the Tika process by manipulating the "Study Assay File Name" parameter. This could lead to unauthorized disclosure of sensitive information contained in those files. Organizations using affected versions (1.8 through 3.3.1 and 4.0.0-alpha-1) should prioritize upgrading to version 3.3.2 or 4.0.0-beta-1 to mitigate this risk.
Original NVD Description
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)