CVE-2014-1972

Apache Tapestry <5.3.6 - DoS/Code Injection

Title source: llm
STIX 2.1

Description

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Scores

EPSS 0.0882
EPSS Percentile 92.6%

Details

CWE
CWE-399
Status published
Products (2)
apache/tapestry < 5.3.5
org.apache.tapestry/tapestry-core 0 - 5.3.6Maven
Published Aug 22, 2015
Tracked Since Feb 18, 2026