{"id":"CVE-2021-27850","details":"A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Recap: Before the fix of CVE-2019-0195 it was possible to download arbitrary class files from the classpath by providing a crafted asset file URL. An attacker was able to download the file `AppModule.class` by requesting the URL `http://localhost:8080/assets/something/services/AppModule.class` which contains a HMAC secret key. The fix for that bug was a blacklist filter that checks if the URL ends with `.class`, `.properties` or `.xml`. Bypass: Unfortunately, the blacklist solution can simply be bypassed by appending a `/` at the end of the URL: `http://localhost:8080/assets/something/services/AppModule.class/` The slash is stripped after the blacklist check and the file `AppModule.class` is loaded into the response. This class usually contains the HMAC secret key which is used to sign serialized Java objects. With the knowledge of that key an attacker can sign a Java gadget chain that leads to RCE (e.g. CommonsBeanUtils1 from ysoserial). Solution for this vulnerability: * For Apache Tapestry 5.4.0 to 5.6.1, upgrade to 5.6.2 or later. * For Apache Tapestry 5.7.0, upgrade to 5.7.1 or later.","aliases":["GHSA-mj8x-cpr8-x39h"],"modified":"2026-07-08T21:26:23.585831Z","published":"2021-04-15T08:15:14.823Z","references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r237ff7f286bda31682c254550c1ebf92b0ec61329b32fbeb2d1c8751%40%3Cusers.tapestry.apache.org%3E"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210528-0002/"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2021/04/15/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tapestry-5","events":[{"introduced":"2672e9847ad56d2b3f83c28319b532b92d6af5c9"},{"fixed":"6f631e9abf8cc08bd269e6aaa1e2f02f5fdf99df"},{"introduced":"e6f2930cddbd22cae01629be1f615cf2d6fae53b"},{"fixed":"ce9c2e8e49669a7d7e68c347f1d95e79ece74ae4"}],"database_specific":{"cpe":"cpe:2.3:a:apache:tapestry:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.4.0"},{"fixed":"5.6.2"},{"introduced":"5.7.0"},{"fixed":"5.7.1"}],"source":"CPE_RANGE"}}],"versions":["5.7.0","5.6.1","5.6.0","5.5.0","v5.5.0-beta-3","5.5.0-beta-2","5.5.0-beta-1","5.5.0-alpha-10","5.5.0-alpha-9","5.5.0-alpha-8","5.5.0-alpha-7","5.5.0-alpha-6","5.5.0-alpha-5","5.5.0-alpha-4","5.5.0-alpha-3","5.5.0-alpha-2","5.5.0-alpha-1","5.4.1","5.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27850.json","vanir_signatures_modified":"2026-07-08T21:26:23Z","vanir_signatures":[{"digest":{"line_hashes":["159671752190956839888202282378949367928","212988593600438698240788561596681224861","150402824245139898289936907603974469370","207029623155520213565375127643927511988"],"threshold":0.9},"id":"CVE-2021-27850-3d3fd187","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/ce9c2e8e49669a7d7e68c347f1d95e79ece74ae4","target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/services/assets/ChecksumPath.java"},"deprecated":false},{"target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/services/assets/ClasspathAssetRequestHandler.java","function":"handleAssetRequest"},"deprecated":false,"digest":{"function_hash":"232093618967286557775373289312729812988","length":358},"id":"CVE-2021-27850-5cf1de52","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/ce9c2e8e49669a7d7e68c347f1d95e79ece74ae4"},{"id":"CVE-2021-27850-ab810d90","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/ce9c2e8e49669a7d7e68c347f1d95e79ece74ae4","target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/internal/services/assets/ClasspathAssetRequestHandler.java"},"deprecated":false,"digest":{"line_hashes":["284378579661446013098373214982608343086","245609843336401262186740818144084784934","112948849334168221397216925333388650612","116575860445620407464036789372413627451","180230887276789205070364326392702033518","129471635234099676860530576604828255839","176310894291988263493138216297014468494","7374610308620645194232873410888271506","154167497598666629364885436505632217520","331756740974280736026018447202652164568","85772867468968786334579016960845652256","50943354071803583411760379717041945802"],"threshold":0.9}},{"target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/modules/AssetsModule.java","function":"contributeClasspathAssetProtectionRule"},"deprecated":false,"digest":{"function_hash":"213502086864649480945332901370929568236","length":355},"id":"CVE-2021-27850-efa768ce","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/ce9c2e8e49669a7d7e68c347f1d95e79ece74ae4"},{"id":"CVE-2021-27850-f8a9af2c","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/tapestry-5/commit/ce9c2e8e49669a7d7e68c347f1d95e79ece74ae4","target":{"file":"tapestry-core/src/main/java/org/apache/tapestry5/modules/AssetsModule.java"},"deprecated":false,"digest":{"line_hashes":["325084393117583620262620650209823759525","186084631470732884168193947828483961294","41847748039724231515164435878922550612","154479519259592631505392215516441662296","132618246455398459529253020840514789992","18603454149079097632474497312196781222","221152263616168605010432095892058100260","304799006751927077211024374152284138732","87865311723003628783949870551226891124","225943124072375650806714898233574474833","221264824833876977157115758248739424515","182726166411873497116278551694059323821","89677137426568927738826226972742766319","290366545461886482092656700758666714087","122355736659493064599834531839041111325","329618629301997668733695800834242132052","192444986788426693737302317086080781271","105904606858499163148828015862678853604","244972727679422975977432677371340504343","292593820687982999560874751656829090815","205695115467772602244120315479781525394"],"threshold":0.9}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}