CVE Vulnerabilities

CVE-2022-30470

Published: Jun 02, 2022 | Modified: Jun 10, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Afian Filerun 20220202 Changing the search_tika_path variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

Affected Software

Name Vendor Start Version End Version
Filerun Afian 2022.02.02 (including) 2022.02.02 (including)

References