Impact
The flaw is an Improper Protection of Alternate Path (CWE‑424). Attackers can manipulate the unpack endpoint when the unsecureFeatures setting is not secured, enabling reference to arbitrary file paths and reading of sensitive files. This leads to information disclosure. No evidence of remote code execution is documented.
Affected Systems
Apache Tika Server versions from 4.0.0‑alpha‑1 up to, but not including, 4.0.0‑beta‑1 are vulnerable. Earlier releases are not affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. An EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote use of the network‑facing unpack endpoint, particularly when the unsecureFeatures configuration is set to an insecure value. No evidence of exploitation has been observed. Upgrading to 4.0.0‑beta‑1 removes the issue.
OpenCVE Enrichment