Re: [CVE-2019-0195] Apache Tapestry vulnerability disclosure

"Nourredine K." <[email protected]> Mon, 7 Oct 2019 16:34:47 +0200
Newsgroups gmane.comp.java.tapestry.user
Message-ID <CAL1+cVBNap0ySDG5Gcq=ZtTvruYC2eQWtrX_ANCW9A7iSDuctA@mail.gmail.com>
--000000000000cc0da8059452f4f3
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello Thiago,

Does this CVE concerns only Tapestry 5.4 ? What about 5.1, 5.2 and 5.3 ?
I think we should create a dedicated jira ticket for each CVE to allow
security dev track Tapestry CVE more easily.

Regards,

Nouredine

Le ven. 13 sept. 2019 =C3=A0 16:11, Thiago H. de Paula Figueiredo <
[email protected]> a =C3=A9crit :

> CVE-2019-0195: File reading Leads Java Deserialization Vulnerability
> Severity: important
> Vendor: The Apache Software Foundation
> Versions affected: all Apache Tapestry versions between 5.4.0, including
> its betas, and 5.4.3
>
> Description:
> Manipulating classpath asset file URLs, an attacker could guess the path =
to
> a known file in the classpath and have it downloaded. If the attacker
> found the file with the value of the tapestry.hmac-passphrase configurati=
on
> symbol, most probably the webapp's AppModule class, the value of this
> symbol could be used to craft a Java deserialization attack, thus running
> malicious injected Java code. The vector would be the t:formdata paramete=
r
> from the Form component.
>
> Mitigation:
> Upgrade to Tapestry 5.4.5, which is a drop-in replacement for any 5.4.x
> version.
>
> Credit:
> Ricter Zheng
>
> --
> Thiago H. de Paula Figueiredo
>

--000000000000cc0da8059452f4f3--