Логотип exploitDog
bind:CVE-2023-49735
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-49735

Количество 4

Количество 4

ubuntu логотип

CVE-2023-49735

около 2 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-49735

около 2 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-49735

около 2 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleRes ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qw4h-3xjj-84cc

около 2 лет назад

Apache Tiles: Unvalidated input may lead to path traversal and XXE

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
debian логотип
CVE-2023-49735

** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleRes ...

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-qw4h-3xjj-84cc

Apache Tiles: Unvalidated input may lead to path traversal and XXE

CVSS3: 7.5
1%
Низкий
около 2 лет назад

Уязвимостей на страницу