Apache Tapestry Unauthenticated RCE (CVE-2019-0195, CVE-2021-27850)
Description
Invicti has detected that the web application is based on Apache Tapestry. Apache Tapestry has a vulnerability that allows an unauthenticated user to download arbitrary class files from the classpath by providing a crafted asset file URL. An attacker can use it to achieve RCE on the server.
Remediation
Upgrade to the latest version of Apache Tapestry