Back

CRITICAL

Apache Tapestry prior to version 4 (EOL) allows RCE though deserialization of untrusted input

Published Dec 2, 2022

Description

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Dec 2, 2022
Updated Aug 3, 2024
Reserved Dec 2, 2022
CISA Vulnrichment
Updated May 1, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 2, 2022
GHSA-VC39-X7W6-6VJ7