#VU20404 Improper Authentication in Apache Tapestry - CVE-2019-10071
Published: August 27, 2019 / Updated: April 28, 2021
Apache Tapestry
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the usage of HMACs to verify the integrity of objects stored on the client side. A remote attacker can bypass authentication process, gain unauthorized access to the application and conduct a timing attack in HMAC verification.