GHSA-c566-2grg-mjwg
CRITICALCVE-2020-17531A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users o
- Affected
- >= 4.0, < 5.0.1
- Fixed in
- 5.0.1
- Weakness
- CWE-502
- Published
- 2022-02-09
- Source
- github