Описание
Improper file downloads in Apache Tapestry
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-13953
- https://lists.apache.org/thread.html/r37dab61fc7f7088d4311e7f995ef4117d58d86a675f0256caa6991eb@%3Cusers.tapestry.apache.org%3E
- https://lists.apache.org/thread.html/r50eb12e8a12074a9b7ed63cbab91d180d19cc23dc1da3ed5b6e1280f%40%3Cusers.tapestry.apache.org%3E
Пакеты
Наименование
org.apache.tapestry:tapestry-core
maven
Затронутые версииВерсия исправления
>= 5.4.0, < 5.6.0
5.6.0
Связанные уязвимости
CVSS3: 5.3
nvd
больше 5 лет назад
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.