QID 981628
QID 981628: Java (maven) Security Update for org.apache.tapestry:tapestry-core (GHSA-89r3-rcpj-h7w6)
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-89r3-rcpj-h7w6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-89r3-rcpj-h7w6 -
github.com/advisories/GHSA-89r3-rcpj-h7w6
CVEs related to QID 981628
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-89r3-rcpj-h7w6 | org.apache.tapestry:tapestry-core |
|