CVE Database
/

CVE-2022-46366

Back to search

CVE-2022-46366

Published: Dec 2, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

VendorProductVersions

Apache Software Foundation

Apache Tapestry

affected
Apache Tapestry - < 4.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now