Apache · Apache Tika · CVE-2018-1335
**Name of the Vulnerable Software and Affected Versions**
Apache Tika versions 1.7 through 1.17
**Description**
The issue allows clients to send specially crafted headers to the tika-server, potentially injecting commands into the server's command line. This affects servers running tika-server and exposed to untrusted clients.
**Recommendations**
For Apache Tika versions 1.7 through 1.17, upgrade to Tika 1.18 to resolve the issue.