CVE-2020-17531

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 0.78 % (82th)
0.78% Progress
Affected Products 1
Advisories 1

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

Weaknesses
CWE-502
Deserialization of Untrusted Data
Related CVEs
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2020-12-08 13:15:13
(3 years ago)
Updated Date
2023-11-07 03:19:13
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Tapestry from 4.0.0 version and prior 5.0.1 version cpe:2.3:a:apache:tapestry >= 4.0.0 < 5.0.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...