org.apache.tiles:tiles-core@2.1.1 vulnerabilities

  • latest version

    3.0.8

  • first published

    17 years ago

  • latest version published

    7 years ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.tiles:tiles-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Expression Language Injection

    Affected versions of this package are vulnerable to Expression Language Injection due to Expression Language (EL) expressions being evaluated twice under certain conditions. An attacker can inject malicious scripts or access sensitive information through the tiles:putAttribute or tiles:insertTemplate JSP tags. If at the first evaluation the EL expression is connected to a user-entered content, it could be maliciously exploited to access the server context.

    How to fix Expression Language Injection?

    Upgrade org.apache.tiles:tiles-core to version 2.1.2 or higher.

    [2.1.0,2.1.2)
    • H
    Path Traversal

    Affected versions of this package are vulnerable to Path Traversal when the DefaultLocaleResolver.LOCALE_KEY attribute on the session is set. This is only exploitable by a user who can control the input to to the DefaultLocaleResolver.LOCALE_KEY attribute.

    NOTE: This vulnerability only affects products that are no longer maintained.

    How to fix Path Traversal?

    There is no fixed version for org.apache.tiles:tiles-core.

    [0,)