CVE detail
CVE-2019-0195 — CVE-2019-0195
Published 2019-09-16 · Modified 2026-06-17 · Vendor apache · Product tapestry · Source nvd
CRITICAL
severity
CVSS-derived band
0.1487
EPSS probability
exploitation probability, 30d
96.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the webapp's AppModule class, the value of this symbol could be used to craft a Java deserialization attack, thus running malicious injected Java code. The vector would be the t:formdata parameter from the Form component.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References