Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
| Software | From | Fixed in |
|---|---|---|
| apache / tika | - | 1.13.x |
| apache / nutch | 2.3.1 | 2.3.1.x |
org.apache.tika / tika-core
|
- | 1.14 |