Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Tapestry
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-1972 1 Apache 1 Tapestry 2020-05-31 7.8 HIGH N/A
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.