{"id":"GHSA-w9mp-p2wp-2xf7","summary":"Improper file downloads in Apache Tapestry","details":"In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.","aliases":["CVE-2020-13953"],"modified":"2023-11-08T04:02:24.140577Z","published":"2022-02-10T20:35:42Z","database_specific":{"nvd_published_at":"2020-09-30T18:15:00Z","cwe_ids":["CWE-552"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-04-22T23:05:56Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13953"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r37dab61fc7f7088d4311e7f995ef4117d58d86a675f0256caa6991eb@%3Cusers.tapestry.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r50eb12e8a12074a9b7ed63cbab91d180d19cc23dc1da3ed5b6e1280f%40%3Cusers.tapestry.apache.org%3E"}],"affected":[{"package":{"name":"org.apache.tapestry:tapestry-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tapestry/tapestry-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.6.0"}]}],"versions":["5.4.0","5.4.1","5.4.2","5.4.3","5.4.4","5.4.5","5.5.0","5.5.0-beta-3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-w9mp-p2wp-2xf7/GHSA-w9mp-p2wp-2xf7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}