Skip to main content

Vendor/product archive

apache / tapestry CVEs

Beta · best-effort

10 CVEs tagged to apache / tapestry5 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-46366

Published Dec 2, 2022

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31781

Published Jul 13, 2022

Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30638

Published Apr 27, 2021

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27850

Published Apr 15, 2021

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The v…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-17531

Published Dec 8, 2020

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13953

Published Sep 30, 2020

In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10071

Published Sep 16, 2019

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could l…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-0207

Published Sep 16, 2019

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0195

Published Sep 16, 2019

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1972

Published Aug 22, 2015

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of serv…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1