OSV 1.4.0 · github-reviewed · 修改于 2021-04-23 07:05
发布时间
2022-02-11 04:35
GitHub 审查时间
2021-04-23 07:05
NVD 发布时间
2020-10-01 02:15
源文件
advisories/github-reviewed/2022/02/GHSA-w9mp-p2wp-2xf7/GHSA-w9mp-p2wp-2xf7.json
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.