CVE-2014-1972

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
22/08/2015
Last modified:
12/04/2025

Description

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:tapestry:*:*:*:*:*:*:*:* 5.3.5 (including)


References to Advisories, Solutions, and Tools