https://seclists.org/oss-sec/2023/q4/254: CVE-2023-49735: Apache Tiles: Unvalidated input may lead to path traversal and XXE
Published Nov 30, 2023
·Updated
Affected Software
1 affected component
Apache tiles<2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2023-49735?
The severity of CVE-2023-49735 is classified as low.
2
What versions of Apache Tiles are affected by CVE-2023-49735?
CVE-2023-49735 affects Apache Tiles versions 2.0.0 and earlier.
3
How does CVE-2023-49735 impact security?
CVE-2023-49735 may lead to path traversal and potentially SSRF or XXE attacks due to unvalidated input.
4
How do I fix CVE-2023-49735?
To fix CVE-2023-49735, upgrade to the latest version of Apache Tiles that is no longer affected.
5
What are the potential exploits of CVE-2023-49735?
Exploiting CVE-2023-49735 can result in unauthorized access to files or services through path traversal and external entity injection.