Re: [CVE-2019-0195] Apache Tapestry vulnerability disclosure
"Thiago H. de Paula Figueiredo" <[email protected]> Mon, 14 Oct 2019 18:56:22 -0300
| Newsgroups | gmane.comp.java.tapestry.user |
|---|---|
| Message-ID | <CAE_88GZcpenjqZLuXN_hRH6P3oU-3oxvDCf928V1aL5LsrGfhQ@mail.gmail.com> |
--000000000000ecc4800594e5f05a Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Mon, Oct 7, 2019 at 11:35 AM Nourredine K. <[email protected]> wrote: > Hello Thiago, > Hello! > Does this CVE concerns only Tapestry 5.4 ? What about 5.1, 5.2 and 5.3 ? > Versions affected: all Apache Tapestry versions between 5.4.0, including its betas, and 5.4.3 > I think we should create a dedicated jira ticket for each CVE to allow > security dev track Tapestry CVE more easily. > > Regards, > > Nouredine > > Le ven. 13 sept. 2019 =C3=A0 16:11, Thiago H. de Paula Figueiredo < > [email protected]> a =C3=A9crit : > > > CVE-2019-0195: File reading Leads Java Deserialization Vulnerability > > Severity: important > > Vendor: The Apache Software Foundation > > Versions affected: all Apache Tapestry versions between 5.4.0, includin= g > > its betas, and 5.4.3 > > > > Description: > > Manipulating classpath asset file URLs, an attacker could guess the pat= h > to > > a known file in the classpath and have it downloaded. If the attacker > > found the file with the value of the tapestry.hmac-passphrase > configuration > > symbol, most probably the webapp's AppModule class, the value of this > > symbol could be used to craft a Java deserialization attack, thus runni= ng > > malicious injected Java code. The vector would be the t:formdata > parameter > > from the Form component. > > > > Mitigation: > > Upgrade to Tapestry 5.4.5, which is a drop-in replacement for any 5.4.x > > version. > > > > Credit: > > Ricter Zheng > > > > -- > > Thiago H. de Paula Figueiredo > > > --=20 Thiago --000000000000ecc4800594e5f05a--