CVE-2020-13953: Medium severity apache tapestry vulnerability
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13953?
CVE-2020-13953 has a medium severity level as it allows file downloads from the WEB-INF folder, potentially exposing sensitive files.
How do I fix CVE-2020-13953?
To mitigate CVE-2020-13953, upgrade Apache Tapestry to version 5.6.4 or later for versions 5.4.0 to 5.5.0, and for versions 5.7.0 to 5.7.2 upgrade to version 5.7.3 or later.
What versions of Apache Tapestry are affected by CVE-2020-13953?
CVE-2020-13953 affects Apache Tapestry versions 5.4.0 to 5.5.0 and versions 5.7.0 to 5.7.2.
What is the impact of exploiting CVE-2020-13953?
Exploiting CVE-2020-13953 can lead to unauthorized access to sensitive files located in the WEB-INF directory.
Are there any workarounds for CVE-2020-13953?
As a workaround for CVE-2020-13953, restricting URL patterns or implementing necessary access controls can help mitigate the risk until a patch is applied.