Re: [CVE-2019-0195] Apache Tapestry vulnerability disclosure

"Thiago H. de Paula Figueiredo" <[email protected]> Mon, 14 Oct 2019 18:56:22 -0300
Newsgroups gmane.comp.java.tapestry.user
Message-ID <CAE_88GZcpenjqZLuXN_hRH6P3oU-3oxvDCf928V1aL5LsrGfhQ@mail.gmail.com>
--000000000000ecc4800594e5f05a
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, Oct 7, 2019 at 11:35 AM Nourredine K. <[email protected]>
wrote:

> Hello Thiago,
>

Hello!


> Does this CVE concerns only Tapestry 5.4 ? What about 5.1, 5.2 and 5.3 ?
>

Versions affected: all Apache Tapestry versions between 5.4.0, including
its betas, and 5.4.3


> I think we should create a dedicated jira ticket for each CVE to allow
> security dev track Tapestry CVE more easily.
>
> Regards,
>
> Nouredine
>
> Le ven. 13 sept. 2019 =C3=A0 16:11, Thiago H. de Paula Figueiredo <
> [email protected]> a =C3=A9crit :
>
> > CVE-2019-0195: File reading Leads Java Deserialization Vulnerability
> > Severity: important
> > Vendor: The Apache Software Foundation
> > Versions affected: all Apache Tapestry versions between 5.4.0, includin=
g
> > its betas, and 5.4.3
> >
> > Description:
> > Manipulating classpath asset file URLs, an attacker could guess the pat=
h
> to
> > a known file in the classpath and have it downloaded. If the attacker
> > found the file with the value of the tapestry.hmac-passphrase
> configuration
> > symbol, most probably the webapp's AppModule class, the value of this
> > symbol could be used to craft a Java deserialization attack, thus runni=
ng
> > malicious injected Java code. The vector would be the t:formdata
> parameter
> > from the Form component.
> >
> > Mitigation:
> > Upgrade to Tapestry 5.4.5, which is a drop-in replacement for any 5.4.x
> > version.
> >
> > Credit:
> > Ricter Zheng
> >
> > --
> > Thiago H. de Paula Figueiredo
> >
>


--=20
Thiago

--000000000000ecc4800594e5f05a--