CVE-2020-17531: Deserialization of Untrusted Data
(updated )
A Java Serialization vulnerability in Apache Tapestry Apache makes it possible to deserialize the sp
parameter even before invoking the page validate method, leading to deserialization without authentication.
References
Detect and mitigate CVE-2020-17531 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →