CVE-2014-1972: Apache Tapestry

High severity, CVSS 7.8. EPSS: 9.6% chance of exploitation in the next 30 days.

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Affected products

  • Apache Tapestry: up to and including 5.3.5

Published 2015-08-22. Last modified 2026-06-17.