← Vulnerability feed

Vulnerability record · CVE-2020-17531 · published 8 December 2020

CVE-2020-17531: Apache tapestry deserialization of untrusted data vulnerability

Apache · Tapestry

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

9.8 CVSS 3.1 Critical EPSS 10.0% · top 4.5% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
10.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2022/12/02/1 Mailing ListThird Party Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://security.netapp.com/advisory/ntap-20210115-0007/ Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/12/02/1 Mailing ListThird Party Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://lists.apache.org/thread.html/r700a6aa234dbff0555d4187bdc8274d7e4c0afbf35b9a3457f09ee76%40%3Cusers.tapestry.apach Mailing ListVendor Advisory
https://security.netapp.com/advisory/ntap-20210115-0007/ Third Party Advisory

Track CVE-2020-17531 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-46366Apache tapestry deserialization of untrusted data vulnerabilityApache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-1…EPSS 3.4%9.8CVE-2021-27850Apache Tapestry unauthenticated RCE via asset URL blacklist bypassApache Tapestry's fix for CVE-2019-0195 used a blacklist that blocks asset URLs ending in .class, .properties or .xml, but appending a trailing slash…EPSS 93%analysed9.8CVE-2019-10071Apache tapestry observable discrepancy vulnerabilityThe code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the…EPSS 8.8%9.8CVE-2019-0195Apache tapestry deserialization of untrusted data vulnerabilityManipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker fou…EPSS 14%7.8CVE-2014-1972Apache tapestry vulnerabilityApache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attac…EPSS 9.6%7.5CVE-2026-61899Apache tapestry information exposure vulnerabilityVulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us…EPSS 0.71%7.5CVE-2022-31781Apache tapestry inefficient regular expression (redos) vulnerabilityApache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially craf…EPSS 1.9%7.5CVE-2021-30638Apache tapestry information exposure vulnerabilityInformation Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specia…EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2020-17531), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.