漏洞描述
Apache Tapestry contains a critical unauthenticated remote code execution vulnerability. Affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. Note that this vulnerability is a bypass of the fix for CVE-2019-0195. Before that fix it was possible to download arbitrary class files from the classpath by providing a crafted asset file URL.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-27850↗lists.apache.orghttps://lists.apache.org/thread.html/r237ff7f286bda31682c254550c1ebf92b0ec61329b32fbeb2d1c8751%40%3Cusers.tapestry.apache.org%3E↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2021/04/15/1↗security.netapp.comhttps://security.netapp.com/advisory/ntap-20210528-0002/↗github.comhttps://github.com/ARPSyndicate/cvemon↗