Lucene search

K
osvGoogleOSV:GHSA-C438-8CVQ-PXXX
HistoryMay 13, 2022 - 1:26 a.m.

Apache Tapestry Unsafe Object Storage

2022-05-1301:26:11
Google
osv.dev
6

0.027 Low

EPSS

Percentile

90.5%

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

References

0.027 Low

EPSS

Percentile

90.5%

Related for OSV:GHSA-C438-8CVQ-PXXX