Back to search
CVE-2019-0207
Published: Sep 16, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
| Vendor | Product | Versions |
|---|---|---|
Apache | Apache Tapestry | affected Apache Tapestry 5.4.0 to 5.4.4 |
References
[tapestry-users] 20190913 CVE-2019-0207: Apache Tapestry vulnerability disclosure
mailing-list
x_refsource_MLIST
[tapestry-users] 20191007 Re: CVE-2019-10071: Apache Tapestry vulnerability disclosure
mailing-list
x_refsource_MLIST
[tapestry-commits] 20200531 svn commit: r1061326 [4/4] - in /websites/production/tapestry/content: ./ cache/
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now