Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wq4c-57mh-5f7g

Опубликовано: 19 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 6.3

Описание

Apache Causeway vulnerable to deserialization in Java

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges. 

This issue affects all current versions.

Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Пакеты

Наименование

org.apache.causeway.commons:causeway-commons

maven
Затронутые версииВерсия исправления

< 3.5.0

3.5.0

Наименование

org.apache.causeway.core:causeway-applib

maven
Затронутые версииВерсия исправления

< 3.5.0

3.5.0

Наименование

org.apache.causeway.core:causeway-core

maven
Затронутые версииВерсия исправления

< 3.5.0

3.5.0

Наименование

org.apache.causeway.viewer:causeway-viewer-wicket

maven
Затронутые версииВерсия исправления

< 3.5.0

3.5.0

EPSS

Процентиль: 72%
0.00737
Низкий

9.3 Critical

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 6.3
nvd
3 месяца назад

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges.  This issue affects all current versions. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

EPSS

Процентиль: 72%
0.00737
Низкий

9.3 Critical

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-502