CVE-2014-1972: Apache Tapestry
High severity, CVSS 7.8. EPSS: 9.6% chance of exploitation in the next 30 days.
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.
Affected products
- Apache Tapestry: up to and including 5.3.5
Published 2015-08-22. Last modified 2026-06-17.