apache tapestry CVE-2021-30638 is a vulnerability in Apache Tapestry
Published on April 27, 2021

An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and later
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.

NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2021-30638 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2021-30638

Want to know whenever a new CVE is published for Apache Tapestry? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Tapestry:

Exploit Probability

EPSS
6.56%
Percentile
93.27%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.