PT-2022-20135 · Afian · Afian Filerun

Published

2022-06-01

·

Updated

2022-06-10

·

CVE-2022-30470

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Afian Filerun version 20220202
Description The issue allows remote code execution in the context of the webserver user by changing the search tika path variable to a custom and previously uploaded jar file.
Recommendations For Afian Filerun version 20220202, avoid using the search tika path variable to point to custom jar files until a fix is available. As a temporary workaround, consider restricting access to the search tika path variable to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-30470

Affected Products

Afian Filerun