Tapestry
Vendor:
First CVE: Aug 22, 2015 · Active for 10 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tapestry over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2015
10 years ago
Most Recent CVE
Dec 2, 2022
1,330 days ago
CVE Severity & Scoring
Tapestry10 CVEs
10%
40%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None9 (90.0%)
Unknown1 (10.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (90.0%)
Unknown1 (10.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27850CRITICAL A critical unauthenticated remote code execution vulnerability was found all recent versions of Apache Tapestry. The affected versions include 5.4.5, 5.5.0, 5.6.2 and 5.7.0. The vu | Apr 15, 2021 | 9.8 | 90 | NO | YES |
CVE-2019-0195CRITICAL Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of t | Sep 16, 2019 | 9.8 | 39 | NO | NO |
CVE-2019-10071CRITICAL The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could le | Sep 16, 2019 | 9.8 | 35 | NO | NO |
CVE-2022-46366CRITICAL Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (al | Dec 2, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-17531CRITICAL A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, | Dec 8, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-30638HIGH Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was c | Apr 27, 2021 | 7.5 | 27 | NO | NO |
CVE-2019-0207HIGH Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perfo | Sep 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2022-31781HIGH Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause cat | Jul 13, 2022 | 7.5 | 24 | NO | NO |
CVE-2014-1972HIGH Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of servi | Aug 22, 2015 | 7.8 | 23 | NO | NO |
CVE-2020-13953MEDIUM In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run. | Sep 30, 2020 | 5.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
10.0% of CVEs· 97th percentile
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Tapestry
Top CWEs
Versions
No cataloged versions.