Re: CVE-2019-10071: Apache Tapestry vulnerability disclosure

"Nourredine K." <[email protected]> Mon, 7 Oct 2019 16:39:04 +0200
Newsgroups gmane.comp.java.tapestry.user
Message-ID <CAL1+cVDVJ6zZJyFkj4DK8H6ZExrcg+N51_FhY7DEgQ_7Q4KbGQ@mail.gmail.com>
--0000000000001733a505945304f9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

  Hello Thiago,

Same question here.

Does this CVE concern only Tapestry 5.4 ? What about 5.3 ?

Regards,

Nouredine

Le ven. 13 sept. 2019 =C3=A0 17:02, Thiago H. de Paula Figueiredo <
[email protected]> a =C3=A9crit :

> I'm afraid I've mad an error. It should have been CVE-2019-10071: New Iss=
ue
> in Fix for CVE-2014-1972
>
>
> On Fri, Sep 13, 2019 at 11:39 AM Thiago H. de Paula Figueiredo <
> [email protected]> wrote:
>
> > CVE-2019-0207: Apache Tapestry 5.4.2 Path Traversal vulnerability
> > Severity: important
> > Vendor: The Apache Software Foundation
> > Versions affected: all Apache Tapestry versions between 5.4.0, includin=
g
> > its betas, and 5.4.3.
> >
> > Description: The code which checks HMAC in form submissions used
> > String.equals() for comparisons, which results in a timing side channel
> for
> > the comparison of the HMAC signatures. This could lead to remote code
> > execution if an attacker is able to determine the correct signature for
> > their payload. The comparison should be done with a constant time
> algorithm
> > instead.
> >
> > Mitigation:
> > Upgrade to Tapestry 5.4.5, which is a drop-in replacement for any 5.4.x
> > version.
> >
> > Credit:
> > David Tomaschik of the Google Security Team
> >
> > --
> > Thiago
> >
>
>
> --
> Thiago
>

--0000000000001733a505945304f9--