{"id":"GHSA-vc39-x7w6-6vj7","summary":"Apache Tapestry allows deserialization of untrusted data","details":"** UNSUPPORTED WHEN ASSIGNED ** Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. \n\nNOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.","aliases":["CVE-2022-46366"],"modified":"2023-11-08T04:10:56.433801Z","published":"2022-12-02T15:30:26Z","database_specific":{"github_reviewed_at":"2022-12-05T23:15:18Z","nvd_published_at":"2022-12-02T14:15:00Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-46366"},{"type":"WEB","url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0041/MNDT-2022-0041.md"},{"type":"WEB","url":"https://lists.apache.org/thread/bwn1vjrvz1hq0wbdzj23wz322244swhj"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/12/02/1"}],"affected":[{"package":{"name":"org.apache.tapestry:tapestry-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tapestry/tapestry-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0"},{"fixed":"5.0.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 4.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-vc39-x7w6-6vj7/GHSA-vc39-x7w6-6vj7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}