Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key. Passing user-controlled data to this key may be relatively common, as it was also used like that to set the language in the 'tiles-test' application shipped with Tiles. This issue affects Apache Tiles from version 2 onwards. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tiles | >= 2.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/8ktm4vxr6vvc1qsxh6ft8jzmom1zl65pMailing ListVendor Advisory
- https://lists.apache.org/thread/8ktm4vxr6vvc1qsxh6ft8jzmom1zl65pMailing ListVendor Advisory
FAQ
What is CVE-2023-49735?
CVE-2023-49735 is a vulnerability with a CVSS score of 7.5 (HIGH). ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path travers...
How severe is CVE-2023-49735?
CVE-2023-49735 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49735?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tiles.