VendorsApachetapestryall versions
Vulnerabilities

Apache Software Foundation Tapestry

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-27850
Bypass of the fix for CVE-2019-0195
Published 2021-04-15 · Modified
10.0EPSS 0.935
CVE-2019-0195
Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the webapp's AppModule class, the value of this symbol could be used to craft a Java deserialization attack, thus running malicious injected Java code. The vector would be the t:formdata parameter from the Form component.
Published 2019-09-16 · Modified
9.8EPSS 0.139
CVE-2020-17531
Deserialization flaw in EOL Tapestry 4.
Published 2020-12-08 · Modified
9.8EPSS 0.100
CVE-2019-10071
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the correct signature for their payload. The comparison should be done with a constant time algorithm instead.
Published 2019-09-16 · Modified
9.8EPSS 0.088
CVE-2022-46366
Apache Tapestry prior to version 4 (EOL) allows RCE though deserialization of untrusted input
Published 2022-12-02 · Modified
9.8EPSS 0.034
CVE-2014-1972
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.
Published 2015-08-22 · Modified
7.8EPSS 0.096
CVE-2021-30638
An Information Disclosure due to insufficient input validation exists in Apache Tapestry 5.4.0 and later
Published 2021-04-27 · Modified
7.5EPSS 0.066
CVE-2019-0207
Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.
Published 2019-09-16 · Modified
7.5EPSS 0.031
CVE-2022-31781
Regular Expression Denial of Service (ReDoS) in ContentType.java. (GHSL-2022-022)
Published 2022-07-13 · Modified
7.5EPSS 0.019
CVE-2026-61899
Apache Tapestry: Possible classpath file download through URL manipulation
Published 2026-08-10 · Analyzed
7.5EPSS 0.007
CVE-2020-13953
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
Published 2020-09-30 · Modified
5.3EPSS 0.027