CVE-2021-30638 is a vulnerability in Apache Tapestry
Published on April 27, 2021
An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and later
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2021-30638 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2021-30638
Want to know whenever a new CVE is published for Apache Tapestry? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Tapestry:- Version Apache Tapestry and below Apache Tapestry 5.6.4 is affected.
- Version Apache Tapestry and below Apache Tapestry 5.7.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.