Re: [CVE-2019-0195] Apache Tapestry vulnerability disclosure
"Nourredine K." <[email protected]> Mon, 7 Oct 2019 16:34:47 +0200
| Newsgroups | gmane.comp.java.tapestry.user |
|---|---|
| Message-ID | <CAL1+cVBNap0ySDG5Gcq=ZtTvruYC2eQWtrX_ANCW9A7iSDuctA@mail.gmail.com> |
--000000000000cc0da8059452f4f3 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hello Thiago, Does this CVE concerns only Tapestry 5.4 ? What about 5.1, 5.2 and 5.3 ? I think we should create a dedicated jira ticket for each CVE to allow security dev track Tapestry CVE more easily. Regards, Nouredine Le ven. 13 sept. 2019 =C3=A0 16:11, Thiago H. de Paula Figueiredo < [email protected]> a =C3=A9crit : > CVE-2019-0195: File reading Leads Java Deserialization Vulnerability > Severity: important > Vendor: The Apache Software Foundation > Versions affected: all Apache Tapestry versions between 5.4.0, including > its betas, and 5.4.3 > > Description: > Manipulating classpath asset file URLs, an attacker could guess the path = to > a known file in the classpath and have it downloaded. If the attacker > found the file with the value of the tapestry.hmac-passphrase configurati= on > symbol, most probably the webapp's AppModule class, the value of this > symbol could be used to craft a Java deserialization attack, thus running > malicious injected Java code. The vector would be the t:formdata paramete= r > from the Form component. > > Mitigation: > Upgrade to Tapestry 5.4.5, which is a drop-in replacement for any 5.4.x > version. > > Credit: > Ricter Zheng > > -- > Thiago H. de Paula Figueiredo > --000000000000cc0da8059452f4f3--