CVE-2022-46366
9.8
CRITICAL · CVSS 3.1 · EPSS 3.5% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.52% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-12-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | tapestry |
References
- http://www.openwall.com/lists/oss-security/2022/12/02/1
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0041/MNDT-2022-0041.md
- https://lists.apache.org/thread/bwn1vjrvz1hq0wbdzj23wz322244swhj
- http://www.openwall.com/lists/oss-security/2022/12/02/1
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0041/MNDT-2022-0041.md
- https://lists.apache.org/thread/bwn1vjrvz1hq0wbdzj23wz322244swhj
→ the Explorer · watch your stack · NVD