Количество 2
Количество 2
CVE-2019-0207
больше 6 лет назад
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
CVSS3: 7.5
EPSS: Низкий
GHSA-89r3-rcpj-h7w6
около 6 лет назад
Path traversal attack on Windows platforms
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-0207 Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform. | CVSS3: 7.5 | 1% Низкий | больше 6 лет назад | |
GHSA-89r3-rcpj-h7w6 Path traversal attack on Windows platforms | CVSS3: 7.5 | 1% Низкий | около 6 лет назад |
Уязвимостей на страницу
20