PT-2015-3696 · Apache · Apache Tapestry
Takeshi Terada
·
Published
2015-08-22
·
Updated
2022-05-13
·
CVE-2014-1972
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Tapestry versions prior to 5.3.6
Description
The issue allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized data, due to the reliance on client-side object storage without proper checks.
Recommendations
For versions prior to 5.3.6, update to version 5.3.6 or later to resolve the issue.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tapestry