Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vc39-x7w6-6vj7

Опубликовано: 02 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache Tapestry allows deserialization of untrusted data

** UNSUPPORTED WHEN ASSIGNED ** Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line.

NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

Пакеты

Наименование

org.apache.tapestry:tapestry-core

maven
Затронутые версииВерсия исправления

>= 3.0, < 4.0

5.0.1

EPSS

Процентиль: 88%
0.03875
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.6
redhat
около 3 лет назад

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

CVSS3: 9.8
nvd
около 3 лет назад

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

EPSS

Процентиль: 88%
0.03875
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502