PT-2022-20135 · Afian · Afian Filerun
Published
2022-06-01
·
Updated
2022-06-10
·
CVE-2022-30470
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Afian Filerun version 20220202
Description
The issue allows remote code execution in the context of the webserver user by changing the
search tika path variable to a custom and previously uploaded jar file.Recommendations
For Afian Filerun version 20220202, avoid using the
search tika path variable to point to custom jar files until a fix is available. As a temporary workaround, consider restricting access to the search tika path variable to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Afian Filerun