Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c566-2grg-mjwg

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Serialization vulnerability in Apache Tapestry

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

Пакеты

Наименование

org.apache.tapestry:tapestry-project

maven
Затронутые версииВерсия исправления

>= 4.0, < 5.0.1

5.0.1

EPSS

Процентиль: 97%
0.36455
Средний

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

EPSS

Процентиль: 97%
0.36455
Средний

9.8 Critical

CVSS3

Дефекты

CWE-502