Lucene search

K
githubGitHub Advisory DatabaseGHSA-C438-8CVQ-PXXX
HistoryMay 13, 2022 - 1:26 a.m.

Apache Tapestry Unsafe Object Storage

2022-05-1301:26:11
CWE-502
GitHub Advisory Database
github.com
5

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

0.027 Low

EPSS

Percentile

90.5%

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Affected configurations

Vulners
Node
org.apache.tapestry\tapestryMatchcore

References

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

0.027 Low

EPSS

Percentile

90.5%

Related for GHSA-C438-8CVQ-PXXX