Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.148458
Category:Denial of Service
Title:Apache Tapestry < 5.8.2 DoS Vulnerability
Summary:Apache Tapestry is prone to a regular expression denial of; service (ReDoS) vulnerability.
Description:Summary:
Apache Tapestry is prone to a regular expression denial of
service (ReDoS) vulnerability.

Vulnerability Insight:
Apache Tapestry is vulnerable to regular expression denial of
service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause
catastrophic backtracking, taking exponential time to complete.

Specifically, this is about the regular expression used on the parameter of the
org.apache.tapestry5.http.ContentType class.

Affected Software/OS:
Apache Tapestry version 5.8.1 and prior.

Solution:
Update to version 5.8.2 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-31781
https://www.openwall.com/lists/oss-security/2022/07/12/3
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.