CVE-2019-0207

Publication date

2019-09-16 16:36:14

Family

apache

State

PUBLISHED

Description

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesnt filter the character ``, so attacker can perform a path traversal attack to read any files on Windows platform.