Security Advisory

CVE-2019-0207

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-09-16 16:36:14
Last updated 2024-08-04 17:44:15
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.