Описание
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.
EPSS
Процентиль: 34%
0.00413
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
CWE-200
Связанные уязвимости
CVSS3: 7.5
github
5 дней назад
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, which fixes this issue.
EPSS
Процентиль: 34%
0.00413
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
CWE-200