QID 995278
Date Published: 2023-09-18
QID 995278: Java (Maven) Security Update for org.apache.tapestry:tapestry-core (GHSA-c438-8cvq-pxxx)
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c438-8cvq-pxxx for updates and patch information.
Vendor References
- GHSA-c438-8cvq-pxxx -
github.com/advisories/GHSA-c438-8cvq-pxxx
CVEs related to QID 995278
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c438-8cvq-pxxx | org.apache.tapestry:tapestry-core |
|