CVE-2020-13953
published 2020-09-30CVE-2020-13953: In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.65%
83.9th percentile
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tapestry | >= 5.4.0 < 5.6.4 | 5.6.4 |
| apache | tapestry | >= 5.7.0 < 5.7.2 | 5.7.2 |
| apache_software_foundation | apache_tapestry | >= Apache Tapestry < Apache Tapestry 5.6.4 | Apache Tapestry 5.6.4 |
| apache_software_foundation | apache_tapestry | >= Apache Tapestry < Apache Tapestry 5.7.2 | Apache Tapestry 5.7.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Information Exposure in Apache Tapestry
ghsa·2022-03-18·CVSS 5.3
CVE-2021-30638 [MEDIUM] CWE-200 Information Exposure in Apache Tapestry
Information Exposure in Apache Tapestry
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.
OSV
Information Exposure in Apache Tapestry
osv·2022-03-18·CVSS 5.3
CVE-2021-30638 [MEDIUM] Information Exposure in Apache Tapestry
Information Exposure in Apache Tapestry
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.
GHSA
Improper file downloads in Apache Tapestry
ghsa·2022-02-10
CVE-2020-13953 [MEDIUM] CWE-552 Improper file downloads in Apache Tapestry
Improper file downloads in Apache Tapestry
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
OSV
Improper file downloads in Apache Tapestry
osv·2022-02-10
CVE-2020-13953 [MEDIUM] Improper file downloads in Apache Tapestry
Improper file downloads in Apache Tapestry
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r37dab61fc7f7088d4311e7f995ef4117d58d86a675f0256caa6991eb%40%3Cusers.tapestry.apache.org%3Ehttps://lists.apache.org/thread.html/r50eb12e8a12074a9b7ed63cbab91d180d19cc23dc1da3ed5b6e1280f%40%3Cusers.tapestry.apache.org%3Ehttps://lists.apache.org/thread.html/r37dab61fc7f7088d4311e7f995ef4117d58d86a675f0256caa6991eb%40%3Cusers.tapestry.apache.org%3Ehttps://lists.apache.org/thread.html/r50eb12e8a12074a9b7ed63cbab91d180d19cc23dc1da3ed5b6e1280f%40%3Cusers.tapestry.apache.org%3E
2020-09-30
Published