PT-2022-27841 · Apache · Apache Tapestry

Ilyass El Hadi

·

Published

2022-12-02

·

Updated

2024-08-03

·

CVE-2022-46366

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tapestry versions 3.x
Description The issue allows deserialization of untrusted data, leading to remote code execution. This problem is similar to but distinct from an issue affecting the 4.x version line. The affected version line, 3.x, is no longer supported by the maintainer.
Recommendations For Apache Tapestry versions 3.x, upgrade to a supported version line of Apache Tapestry.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-46366
GHSA-VC39-X7W6-6VJ7

Affected Products

Apache Tapestry