Apache Tapestry ClasspathAssetRequestHandler Information Disclosure Vulnerability

Strike ID:
E25-caui1
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2021

Description

This strike exploits an information disclosure vulnerability in Apache Tapestry. The vulnerability resides in the ClasspathAssetRequestHandler class, specifically in the handleAssetRequest() function, due to improper validation of user input and URL manipulation. A remote, unauthenticated attacker can exploit this flaw by sending a crafted HTTP request, potentially leading to the exposure of sensitive files such as application classes, XML, and property files, which could further enable remote code execution.

CVE

References