CVE detail
CVE-2019-0207 — CVE-2019-0207
Published 2019-09-16 · Modified 2026-06-17 · Vendor apache · Product tapestry · Source nvd
HIGH
severity
CVSS-derived band
0.0309
EPSS probability
exploitation probability, 30d
87.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References