Information Disclosure in Apache Tapestry Web Applications
CVE-2020-13953
5.3MEDIUM
What is CVE-2020-13953?
In specific versions of Apache Tapestry, an attacker can exploit a malformed URL request to access sensitive files within the WEB-INF directory of the deployed web application. This vulnerability allows unauthorized access to files that may contain sensitive configuration data or application logic, increasing the risk of data exposure. Organizations using affected versions of Apache Tapestry should apply security patches and review application configurations to mitigate potential threats.
Affected Version(s)
Apache Tapestry Apache Tapestry from 5.4.0 to 5.5.0