CVE-2020-17531
published 2020-12-08CVE-2020-17531: A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.73%
95.0th percentile
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tapestry | >= 3.0.0 < 4.0.0 | 4.0.0 |
| apache | tapestry | >= 4.0.0 < 5.0.1 | 5.0.1 |
| apache_software_foundation | apache_tapestry | >= Apache Tapestry < 4.0.0 | 4.0.0 |
| fasterxml | jackson-databind | >= 0 < 2.4.2-3ubuntu0.1~esm2 | 2.4.2-3ubuntu0.1~esm2 |
Detection & IOCsextracted from sources · hover to see the quote
- ·The provided sources describe CVE-2022-46366 (Apache Tapestry 3.x deserialization RCE), not CVE-2020-17531 (Apache Tapestry 4.x deserialization RCE). No operational intelligence specific to CVE-2020-17531 is present in the supplied documents. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Tapestry: prior to version 4 (EOL) allows RCE though deserialization of untrusted input
vendor_redhat·2022-12-02·CVSS 9.8
CVE-2022-46366 [CRITICAL] CWE-502 Tapestry: prior to version 4 (EOL) allows RCE though deserialization of untrusted input
Tapestry: prior to version 4 (EOL) allows RCE though deserialization of untrusted input
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.
Package: Tapestry (Migration Toolkit for Applications 6) - Not affected
Package: Tapestry (Migration Toolkit for Runtimes) - Not affected
Package: Tapestry (Red Hat Decision Manager 7) - Not affected
Package: Tapestry (Red Hat Fuse 7) - Not affected
Package: Tapestry (Red Hat JBoss Data Gri
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Build Request (jackson-databind) — CVE-2019-17531
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2019-17531 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Build Request (jackson-databind) — CVE-2019-17531
Oracle Oracle Fusion Middleware Risk Matrix: Build Request (jackson-databind) vulnerability
CVE: CVE-2019-17531
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (jackson-databind) — CVE-2019-17531
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-17531 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (jackson-databind) — CVE-2019-17531
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (jackson-databind) vulnerability
CVE: CVE-2019-17531
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
GHSA
Apache Tapestry allows deserialization of untrusted data
ghsa·2022-12-02·CVSS 9.8
CVE-2022-46366 [CRITICAL] CWE-502 Apache Tapestry allows deserialization of untrusted data
Apache Tapestry allows deserialization of untrusted data
** UNSUPPORTED WHEN ASSIGNED ** Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line.
NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.
OSV
Apache Tapestry allows deserialization of untrusted data
osv·2022-12-02·CVSS 9.8
CVE-2022-46366 [CRITICAL] Apache Tapestry allows deserialization of untrusted data
Apache Tapestry allows deserialization of untrusted data
** UNSUPPORTED WHEN ASSIGNED ** Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line.
NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.
GHSA
Serialization vulnerability in Apache Tapestry
ghsa·2022-02-09
CVE-2020-17531 [CRITICAL] CWE-502 Serialization vulnerability in Apache Tapestry
Serialization vulnerability in Apache Tapestry
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.
OSV
Serialization vulnerability in Apache Tapestry
osv·2022-02-09
CVE-2020-17531 [CRITICAL] Serialization vulnerability in Apache Tapestry
Serialization vulnerability in Apache Tapestry
A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.
OSV
jackson-databind vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-11307 jackson-databind vulnerabilities
jackson-databind vulnerabilities
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,
CVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/12/02/1https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apache.org%3Ehttps://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210115-0007/http://www.openwall.com/lists/oss-security/2022/12/02/1https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apache.org%3Ehttps://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210115-0007/
2020-12-08
Published