[MAVEN:GHSA-C438-8CVQ-PXXX] Apache Tapestry Unsafe Object Storage

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Package Affected Version
pkg:maven/org.apache.tapestry/tapestry-core < 5.3.6
Package Fixed Version
pkg:maven/org.apache.tapestry/tapestry-core = 5.3.6
ID
MAVEN:GHSA-C438-8CVQ-PXXX
Severity
high
URL
https://github.com/advisories/GHSA-c438-8cvq-pxxx
Published
2022-05-13T01:26:11
(2 years ago)
Modified
2023-08-16T05:02:13
(13 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.tapestry/tapestry-core org.apache.tapestry tapestry-core < 5.3.6
Fixed pkg:maven/org.apache.tapestry/tapestry-core org.apache.tapestry tapestry-core = 5.3.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...