CVE-2020-13953: Apache Tapestry
Medium severity, CVSS 5.3. EPSS: 2.7% chance of exploitation in the next 30 days.
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
Affected products
- Apache Tapestry: from 5.4.0, before 5.6.4 (fixed in 5.6.4); from 5.7.0, before 5.7.2 (fixed in 5.7.2)
Published 2020-09-30. Last modified 2026-06-17.