Apache

Tapestry

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.79%
  • Published 02.12.2022 14:15:10
  • Last modified 21.11.2024 07:30:28

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affect...

  • EPSS 1.17%
  • Published 13.07.2022 08:15:07
  • Last modified 21.11.2024 07:05:18

Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause catastrophic backtracking, taking exponential time to complete. Specifica...

  • EPSS 5.31%
  • Published 27.04.2021 19:15:07
  • Last modified 21.11.2024 06:04:20

Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apac...

Exploit
  • EPSS 94.22%
  • Published 15.04.2021 08:15:14
  • Last modified 21.11.2024 05:58:38

A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vulnerability I have found is a bypass of the fix for CVE-2019-0195. Rec...

  • EPSS 17.51%
  • Published 08.12.2020 13:15:13
  • Last modified 21.11.2024 05:08:18

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 ...

  • EPSS 1.8%
  • Published 30.09.2020 18:15:21
  • Last modified 21.11.2024 05:02:13

In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

  • EPSS 9.82%
  • Published 16.09.2019 18:15:10
  • Last modified 21.11.2024 04:18:20

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the co...

  • EPSS 1.37%
  • Published 16.09.2019 17:15:13
  • Last modified 21.11.2024 04:16:29

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.

  • EPSS 6.43%
  • Published 16.09.2019 16:15:10
  • Last modified 21.11.2024 04:16:27

Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the we...

  • EPSS 8.82%
  • Published 22.08.2015 23:59:00
  • Last modified 12.04.2025 10:46:40

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serial...