Rewterz
Rewterz Threat Advisory – CVE-2022-22982 – VMware vCenter Server server-side Vulnerability
July 14, 2022
Rewterz
Rewterz Threat Advisory –CVE-2020-4138 – IBM SiteProtector Vulnerability
July 14, 2022

Rewterz Threat Advisory –CVE-2022-31781 – Apache Tapestry Vulnerability

Severity

High

Analysis Summary

CVE-2022-31781

Apache Tapestry is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the handling of Content Types. By sending a specially-crafted regex input using Content Types, a remote attacker could exploit this vulnerability to cause catastrophic backtracking, and results in a denial of service condition.

Impact

  • Denial of Service

Indicators Of Compromise

CVE

  • CVE-2022-31781

Affected Vendors

Apache

Affected Products

Apache Tapestry 5.8.1

Remediation

Upgrade to the latest version of Apache Tapestry, available from the Apache Web site.

Apache Web site