E25-caui1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2021
Description
This strike exploits an information disclosure vulnerability in Apache Tapestry. The vulnerability resides in the ClasspathAssetRequestHandler class, specifically in the handleAssetRequest() function, due to improper validation of user input and URL manipulation. A remote, unauthenticated attacker can exploit this flaw by sending a crafted HTTP request, potentially leading to the exposure of sensitive files such as application classes, XML, and property files, which could further enable remote code execution.
CVE
References
https://github.com/Ovi3/CVE_2021_27850_POC