Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghm8-mmx7-xvg2

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Information Exposure in Apache Tapestry

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.

Пакеты

Наименование

org.apache.tapestry:tapestry-core

maven
Затронутые версииВерсия исправления

>= 5.4.0, < 5.6.4

5.6.4

Наименование

org.apache.tapestry:tapestry-core

maven
Затронутые версииВерсия исправления

>= 5.7.0, < 5.7.2

5.7.2

EPSS

Процентиль: 90%
0.05311
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.

EPSS

Процентиль: 90%
0.05311
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-863