CVE-2020-13953
30.09.2020, 18:15
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.Enginsight
Vendor | Product | Version |
---|---|---|
apache | tapestry | 5.4.0 ≤ 𝑥 < 5.6.4 |
apache | tapestry | 5.7.0 ≤ 𝑥 < 5.7.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References