cbcvebase.
CVE-2020-17531
published 2020-12-08

CVE-2020-17531: A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.73%
95.0th percentile
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachetapestry>= 3.0.0 < 4.0.04.0.0
apachetapestry>= 4.0.0 < 5.0.15.0.1
apache_software_foundationapache_tapestry>= Apache Tapestry < 4.0.04.0.0
fasterxmljackson-databind>= 0 < 2.4.2-3ubuntu0.1~esm22.4.2-3ubuntu0.1~esm2

Detection & IOCsextracted from sources · hover to see the quote

  • ·The provided sources describe CVE-2022-46366 (Apache Tapestry 3.x deserialization RCE), not CVE-2020-17531 (Apache Tapestry 4.x deserialization RCE). No operational intelligence specific to CVE-2020-17531 is present in the supplied documents.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.