SB2019082713 - Authentication bypass in Apache Tapestry
Published: August 27, 2019 Updated: April 28, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2019-10071)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the usage of HMACs to verify the integrity of objects stored on the client side. A remote attacker can bypass authentication process, gain unauthorized access to the application and conduct a timing attack in HMAC verification.
Remediation
Install update from vendor's website.