High severity7.5NVD Advisory· Published Apr 27, 2021· Updated Jun 17, 2026
CVE-2021-30638
CVE-2021-30638
Description
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tapestry:tapestry-coreMaven | >= 5.4.0, < 5.6.4 | 5.6.4 |
org.apache.tapestry:tapestry-coreMaven | >= 5.7.0, < 5.7.2 | 5.7.2 |
Affected products
3Patches
Vulnerability mechanics
References
8- www.openwall.com/lists/oss-security/2021/04/27/3nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-ghm8-mmx7-xvg2ghsaADVISORY
- lists.apache.org/thread.html/r37dab61fc7f7088d4311e7f995ef4117d58d86a675f0256caa6991eb%40%3Cusers.tapestry.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-30638ghsaADVISORY
- security.netapp.com/advisory/ntap-20210528-0004/nvdThird Party Advisory
- www.zerodayinitiative.com/advisories/ZDI-21-491/nvdThird Party AdvisoryVDB Entry
- security.netapp.com/advisory/ntap-20210528-0004ghsaWEB
- www.zerodayinitiative.com/advisories/ZDI-21-491ghsaWEB
News mentions
0No linked articles in our index yet.