CVE-2014-1972: High severity apache tapestry vulnerability
Published Aug 22, 2015
·Updated
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.
Affected Software
2 affected componentsFixes available
maven/org.apache.tapestry:tapestry-core<5.3.6
5.3.6
Apache Tapestry<=5.3.5
Event History
Aug 22, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 13, 2022
Advisory Published
01:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-1972?
CVE-2014-1972 has a severity rating that can lead to denial of service or arbitrary code execution.
2
How do I fix CVE-2014-1972?
To fix CVE-2014-1972, upgrade Apache Tapestry to version 5.3.6 or later.
3
What systems are affected by CVE-2014-1972?
CVE-2014-1972 affects Apache Tapestry versions prior to 5.3.6.
4
What type of attack does CVE-2014-1972 enable?
CVE-2014-1972 enables remote attackers to cause denial of service or execute arbitrary code.
5
Why is CVE-2014-1972 a security concern?
CVE-2014-1972 is a security concern because it relies on client-side object storage that can be manipulated by attackers.